EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium
A penetration tester is analyzing a web application that stores user session IDs in cookies. The tester notices that the session ID remains constant even after a user logs out and then logs back in. This behavior could indicate a vulnerability related to session management. Which specific attack could exploit this flaw?
- AInsecure Direct Object Reference (IDOR)
- BCross-Site Scripting (XSS)
- CSession Hijacking
- DSession Fixation
Show answer & explanationAnswer & explanation
Correct answer: D. Session Fixation
If a session ID remains constant after logout and re-login, it indicates that the server is not invalidating and regenerating session IDs properly. This specific flaw is a classic condition for a Session Fixation attack, where an attacker can provide a victim with a pre-determined session ID, and if the victim logs in with it, the attacker can then use that same ID to impersonate the victim.
Why the other options are wrong
- A. IDOR involves accessing resources by manipulating object IDs, unrelated to session ID persistence across logins.
- B. XSS involves injecting malicious scripts; it's a different mechanism, though it could potentially be used to *facilitate* session fixation by injecting a pre-set cookie.
- C. Session Hijacking involves stealing an *active* session, but doesn't necessarily rely on the ID being fixed across logins.
Session Fixation
An attack where the attacker tricks a user into authenticating with a session ID chosen by the attacker, allowing the attacker to impersonate the user.
- Relies on the server not regenerating session IDs upon successful authentication.
- Often facilitated by social engineering or XSS to deliver the fixed session ID.
- Countermeasure: regenerate session IDs on every successful login.
Memory trick: Fixed sessions mean an attacker can 'fix' their entry.