EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium

A penetration tester is analyzing a web application that stores user session IDs in cookies. The tester notices that the session ID remains constant even after a user logs out and then logs back in. This behavior could indicate a vulnerability related to session management. Which specific attack could exploit this flaw?

  1. AInsecure Direct Object Reference (IDOR)
  2. BCross-Site Scripting (XSS)
  3. CSession Hijacking
  4. DSession Fixation
Show answer & explanation

Correct answer: D. Session Fixation

If a session ID remains constant after logout and re-login, it indicates that the server is not invalidating and regenerating session IDs properly. This specific flaw is a classic condition for a Session Fixation attack, where an attacker can provide a victim with a pre-determined session ID, and if the victim logs in with it, the attacker can then use that same ID to impersonate the victim.

Why the other options are wrong

  • A. IDOR involves accessing resources by manipulating object IDs, unrelated to session ID persistence across logins.
  • B. XSS involves injecting malicious scripts; it's a different mechanism, though it could potentially be used to *facilitate* session fixation by injecting a pre-set cookie.
  • C. Session Hijacking involves stealing an *active* session, but doesn't necessarily rely on the ID being fixed across logins.

Session Fixation

An attack where the attacker tricks a user into authenticating with a session ID chosen by the attacker, allowing the attacker to impersonate the user.

  • Relies on the server not regenerating session IDs upon successful authentication.
  • Often facilitated by social engineering or XSS to deliver the fixed session ID.
  • Countermeasure: regenerate session IDs on every successful login.

Memory trick: Fixed sessions mean an attacker can 'fix' their entry.

More Web Application Hacking questions