EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium

A penetration tester is evaluating a web application's login mechanism. They observe that the application uses a fixed, predictable session ID after successful authentication. If an attacker can obtain a valid session ID from a legitimate user before they log in, and then use that ID to authenticate themselves, which attack vector is the application vulnerable to?

  1. ASession Hijacking
  2. BSession Fixation
  3. CBroken Access Control
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: B. Session Fixation

Session Fixation occurs when an attacker can force a user's session ID to a known value, which they can then use to impersonate the user after they successfully log in. The key is the attacker providing a 'fixed' session ID before the legitimate user authenticates.

Why the other options are wrong

  • A. Session Hijacking involves stealing an *already established* session from an authenticated user.
  • C. Broken Access Control refers to flaws in authorization logic, not session management.
  • D. XSS injects client-side scripts, which might facilitate session hijacking, but it's not the primary vulnerability described here.

Session Fixation

A web application vulnerability that allows an attacker to 'fix' a user's session ID to a value known by the attacker. If the user then logs in with this fixed session ID, the attacker can use the same ID to impersonate the user.

  • Attacker forces a specific session ID on a user.
  • Occurs *before* user authentication.
  • Exploits lack of session ID regeneration upon login.

Memory trick: Fix the ID before login, then your access will begin.

More Web Application Hacking questions