Skip to content

Session Fixation

Web applications rely on session management and authentication tokens to maintain user state and enforce access control. Attackers can exploit weaknesses in these mechanisms to bypass authentication, impersonate users, or maintain persistent access. This section explores session fixation and token manipulation techniques, including how to detect and exploit them during authorized testing.


Overview

Session Fixation

Session fixation occurs when an attacker assigns a known session ID to a user, allowing them to hijack the session after the user authenticates. This is often achieved by forcing the user to log in with a pre-set session ID, which the attacker can then use to access the user’s account.

Token Manipulation

Authentication tokens (e.g., JWTs, OAuth tokens) are often used to maintain user sessions. Attackers may manipulate these tokens by:
- Replaying stolen tokens to impersonate users.
- Predicting token values based on patterns.
- Exploiting XSS to steal tokens from victims’ browsers.

These techniques highlight the importance of secure session and token management practices.


Exploitation Techniques

1. Session Fixation via HTTP Headers

An attacker can force a victim to accept a fixed session ID by embedding it in a URL or HTTP header. For example:

curl -v https://vulnerable-app.com/login?session=attacker_session_id
If the application accepts the session ID without validation, the attacker can later access the user’s session by replaying the session cookie.

2. Token Manipulation via XSS

If an application exposes tokens in client-side scripts (e.g., via document.cookie), an attacker can steal them using XSS. Example:

// Malicious script injected via XSS
document.cookie = "auth_token=stolen_token; Secure; HttpOnly";
This script could be delivered via a phishing link or a compromised third-party widget.

3. Token Replay Attacks

Attackers can intercept and reuse valid tokens by:
- Sniffing network traffic (e.g., using Wireshark).
- Intercepting requests with tools like Burp Suite.
Example:

# Replay a stolen token using curl
curl -X POST https://api.vulnerable.com/secure-endpoint \
  -H "Authorization: Bearer stolen_token"

Attackers can force a user to accept a fixed session ID by embedding it in a malicious link:

# Example: Force user to log in with a fixed session ID
https://vulnerable-app.com/login?session=attacker_session_id
If the application does not regenerate the session ID upon login, the attacker gains access.


Mitigation Strategies

  1. Regenerate Session IDs on Login: Ensure session IDs are randomized and not reused after authentication.
  2. Use Secure Cookies: Set the Secure and HttpOnly flags to prevent cookie theft via XSS.
  3. Token Binding: Bind tokens to specific channels (e.g., IP addresses, user agents) to prevent replay attacks.
  4. Rate Limiting: Limit the number of login attempts or token requests to deter brute-force attacks.
  5. Token Expiry: Implement short-lived tokens with refresh mechanisms to minimize exposure.

Key takeaways

  • Session fixation exploits rely on predictable or forced session IDs, often delivered via URLs or headers.
  • Token manipulation techniques (e.g., XSS, replay attacks) require careful handling of client-side data.
  • Secure session management practices, such as ID regeneration and secure cookie attributes, are critical to mitigating these risks.
  • Tools like Burp Suite and Wireshark can help detect and analyze session/token vulnerabilities during testing.
  • Always validate and sanitize user inputs to prevent injection-based attacks that could expose session data.