SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium
During a security audit, it was discovered that an internal web application transmits user session IDs in the URL query string. This practice poses a significant security risk. Which of the following is the primary risk associated with transmitting session IDs in the URL?
- AVulnerability to man-in-the-middle attacks.
- BIncreased network latency due to larger URLs.
- CExposure of session IDs in browser history, logs, and referrer headers.
- DIncompatibility with modern web browsers.
Show answer & explanationAnswer & explanation
Correct answer: C. Exposure of session IDs in browser history, logs, and referrer headers.
Transmitting session IDs in the URL query string exposes them to various forms of leakage, including browser history, web server logs, and referrer headers when navigating to other sites. This significantly increases the risk of session hijacking.
Why the other options are wrong
- A. Man-in-the-middle attacks are a risk for unencrypted traffic, but exposing session IDs in the URL is a separate, persistent risk even with HTTPS.
- B. While URLs might be slightly larger, the performance impact is usually negligible and not the primary security risk.
- D. Most modern browsers still technically support this, but it's an insecure practice, not a compatibility issue.
Session ID Management
The process of securely creating, transmitting, and validating session identifiers to maintain stateful communication between a user and a web application.
- Session IDs should be long, random, and unpredictable.
- Never transmit session IDs in URLs (query strings).
- Use HTTPS and HTTP-only, secure, and samesite cookies for session IDs.
Memory trick: Web sessions need a secret handshake, not a shouted password.