After login the password is irrelevant; the session token is the credential. Attackers steal it through XSS reading the cookie, malware, network snooping on unencrypted connections, or session fixation — planting a known token for the victim to log into.
Defence is layered: HttpOnly cookies keep JavaScript away from the token, Secure and SameSite keep it off hostile requests, rotation on login kills fixation, and binding checks — device, IP drift — catch tokens walking. Short expiry plus invalidation on logout bounds the damage when one does leak.
Related terms
Cross-site scripting (XSS)
An attack that injects hostile JavaScript into a page other people view — the browser runs the attacker's code with the victim's session.
CSRF
Cross-site request forgery — tricking a logged-in browser into sending a request the user never meant, riding on their cookies.
TLS
Transport Layer Security — the encryption layer behind HTTPS that keeps traffic private and proves the site you reached is the site you meant.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
