DFIELDSOLUTIONS

Security

GlossarySession hijacking

Stealing the token that proves a logged-in session — whoever holds it is you, no password needed.

After login the password is irrelevant; the session token is the credential. Attackers steal it through XSS reading the cookie, malware, network snooping on unencrypted connections, or session fixation — planting a known token for the victim to log into.

Defence is layered: HttpOnly cookies keep JavaScript away from the token, Secure and SameSite keep it off hostile requests, rotation on login kills fixation, and binding checks — device, IP drift — catch tokens walking. Short expiry plus invalidation on logout bounds the damage when one does leak.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain