# Session hijacking

> Stealing the token that proves a logged-in session — whoever holds it is you, no password needed.

After login the password is irrelevant; the session token is the credential. Attackers steal it through XSS reading the cookie, malware, network snooping on unencrypted connections, or session fixation — planting a known token for the victim to log into.

Defence is layered: HttpOnly cookies keep JavaScript away from the token, Secure and SameSite keep it off hostile requests, rotation on login kills fixation, and binding checks — device, IP drift — catch tokens walking. Short expiry plus invalidation on logout bounds the damage when one does leak.

## Related terms

- https://dfieldsolutions.com/en/glossary/xss.md
- https://dfieldsolutions.com/en/glossary/csrf.md
- https://dfieldsolutions.com/en/glossary/tls.md

---

Source: https://dfieldsolutions.com/en/glossary/session-hijacking
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
