session hijacking

Intermediate 💻 Tech / IT

Definition

An attack where someone steals an active session token to impersonate a logged-in user, like grabbing someone's coat check ticket and claiming their jacket. Except the jacket is their bank account.

Example Usage

We need to implement proper HTTPS and secure cookies to prevent session hijacking on the login flow.

Origin

Emerged with web authentication systems in the mid-1990s as cookies became the standard for session management

Fun Fact

In 2010, a Firefox extension called Firesheep made session hijacking on public WiFi so easy that coffee shops became the most dangerous place to check your email.

Source: Web security and network attack methodology documentation

Related Terms

Translate This Term

See “session hijacking” in Corporate Speak, Gen-Z Slang, Pirate Speak, and more.

Try the Translator