EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium
A penetration tester is evaluating a web application's login mechanism. They observe that the application uses a fixed, predictable session ID after successful authentication. If an attacker can obtain a valid session ID from a legitimate user before they log in, and then use that ID to authenticate themselves, which attack vector is the application vulnerable to?
- ASession Hijacking
- BSession Fixation
- CBroken Access Control
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. Session Fixation
Session Fixation occurs when an attacker can force a user's session ID to a known value, which they can then use to impersonate the user after they successfully log in. The key is the attacker providing a 'fixed' session ID before the legitimate user authenticates.
Why the other options are wrong
- A. Session Hijacking involves stealing an *already established* session from an authenticated user.
- C. Broken Access Control refers to flaws in authorization logic, not session management.
- D. XSS injects client-side scripts, which might facilitate session hijacking, but it's not the primary vulnerability described here.
Session Fixation
A web application vulnerability that allows an attacker to 'fix' a user's session ID to a value known by the attacker. If the user then logs in with this fixed session ID, the attacker can use the same ID to impersonate the user.
- Attacker forces a specific session ID on a user.
- Occurs *before* user authentication.
- Exploits lack of session ID regeneration upon login.
Memory trick: Fix the ID before login, then your access will begin.