166 terms · 75/46/45
kompozit · edukator režim · za predavanje i PDF

Session Hijacking

Pretnja u centru, tehnike kojima se izvodi levo, odbrane koje je suzbijaju desno. Ispod — mapa faza napada: kojom tehnikom se ulazi i koja odbrana je presreće.

↘ Techniques used to carry it out5

Techniques used to carry it out. Klik vodi na stranicu pojma.

threat · № 019 · identity

Session Hijacking

When you log in, the service opens a session — a state that remembers you are you, together with everything that goes with it, such as your preferences and settings. The main benefit is that you do not have to type a password every few minutes as you move through the features. That session is marked by an identifier, usually held in a browser cookie. Session hijacking is the taking over of a session that is already open. The attacker does not attack the login; they slip into a session that has already passed authentication and carry on operating the service in your name.

↓ izvor: prvi po vezama Najčešći ulaz: Credential Abuse. Ključna odbrana: Logging & Monitoring.

↗ How it is defended against5