Session fixation: A type of attack where an attacker manipulates the session identifier, or “session ID,” of a user’s session to gain unauthorized access to their account. It is often used in web-based attacks, where the attacker may trick a user into using a compromised session ID. For instance, an attacker may send a user a malicious link with a pre-set session ID, allowing the attacker to hijack the user’s session.
Categories: CC D5: Security Operations | CCSP D4: Cloud Application Security | CISM D4: Incident Management | CISSP D7: Security Operations | Security+ D2: Threats Vulnerabilities and Mitigations | SSCP D6: Network and Communication Security
« Back to Glossary Index