session hijacking
Home > Software Quality Glossary > Definition - session hijacking
EMAIL THIS
Glossary - powered by WhatIs.com
 BROWSE ALPHABETICALLY:    A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #    
Search for: in Full Target Search with Google

session hijacking

Session hijacking, also known as TCP session hijacking, is a method of taking over a Web user session by surreptitiously obtaining the session ID and masquerading as the authorized user. Once the user's session ID has been accessed (through session prediction), the attacker can masquerade as that user and do anything the user is authorized to do on the network.

The session ID is normally stored within a cookie or URL. For most communications, authenticationprocedures are carried out at set up. Session hijacking takes advantage of that practice by intruding in real time, during a session. The intrusion may or may not be detectable, depending on the user's level of technical knowledge and the nature of the attack. If a Web site does not respond in the normal or expected way to user input or stops responding altogether for an unknown reason, session hijacking is a possible cause.

Read more about it:
>>  Microsoft's TechNet Magazine has an article about preventing session hijacking.
>>  Imperva describes how session hijacking works.

Last updated on: Sep 25, 2006

WHITE PAPERS  
Expert Ebook: Mastering PCI
Information Security Magazine Sponsored by: Breach, Cisco, Fiberlink, Rapid7, Sentrigo, Solidcore, Thawte, Tripwire, and Utimaco

The IBM Rational AppScan Lifecycle Solution
IBM

Rational AppScan Security eKit
IBM

Trial Download: Rational AppScan
IBM

PCI Compliance Cut Costs, Not Corners with Third Brigade®
Third Brigade

>> More White Papers
  WHAT'S NEW
 1. Web application security
 2. The Ajax Experience: Sept 29 - Oct 1
 3. Scrum and requirements gathering
 4. Software testing fundamentals


About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts