Pretnje
7 direktnih pogodaka-
№ 019
Session Hijacking When you log in, the service opens a session — a state that remembers you are you, together with everything that goes with it, such as your preferences and sett …pretnja · identity
-
№ 041
Cross-Site Request Forgery … fact that a browser automatically sends existing session cookies to a site where the user is already logged in. The attacker does not need to know the password …pretnja · applications
-
№ 012
Infostealer … credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of it is of interest. It stays in contact with the att …pretnja · malware
-
№ 040
Cross-Site Scripting … ter. Carried out in the right place, it can cause session theft, account takeover or a covert way into a business application.pretnja · applications
-
№ 047
Path Traversal … erable VPN or network device allows files holding sessions or credentials to be read through path manipulation.pretnja · applications
-
№ 034
QR phishing - Quishing … places. The attack is simple: the user moves the session out of a controlled business environment onto a personal phone themselves.pretnja · social eng.
-
№ 062
Shared Account Abuse … hnical limitation, the access belongs behind PAM, session recording and credentials issued for a limited time.pretnja · trust
Tehnike
3 direktna pogotka-
№ 020
Access Token Manipulation … s stealing or manipulating authentication tokens, session cookies, or access keys to assume the identity of a legitimate user or service. The attacker can use a …tehnika · privileges
-
№ 009
AiTM … phishing steals a password; AiTM steals the live session. The victim gets a link, lands on a proxy that looks exactly like the real login (because it forwards …tehnika · initial access
-
№ 028
Network Sniffing Can capture credentials, session tokens, email content, and API keys.tehnika · discovery
Odbrane
2 direktna pogotka-
№ 008
Multi-Factor Authentication Multi-factor authentication requires two or more independent proofs of identity at login. It typically combines something the user knows (password), something they possess (phone, hardware key), and something they are (biometrics).odbrana · identity / access
-
№ 010
Privileged Access Management … edentials, automatic password rotation, real-time session monitoring, and just-in-time access approval instead of permanent standing access.odbrana · identity / access