What type of session hijacking attack is shown in the exhibit?
A. Cross-site scripting Attack
B. SQL Injection Attack
C. Token sniffing Attack
D. Session Fixation Attack
3 Comments on “What type of session hijacking attack is shown in the exhibit?”
Ghost Mansays:
A is the Ans.
D33pBr3dtsays:
Ans: D
Session Fixation – Social engineering is involved in this attack.
This photo is fairly misleading. Step 1 is the attacker logging into the vulnerable web application. The attacker then sends this ID to the victim who logs into the web application. Session ID is known to the attacker, just reload the browser. Hence the term fixation.
A is the Ans.
Ans: D
Session Fixation – Social engineering is involved in this attack.
This photo is fairly misleading. Step 1 is the attacker logging into the vulnerable web application. The attacker then sends this ID to the victim who logs into the web application. Session ID is known to the attacker, just reload the browser. Hence the term fixation.
100% D
2ez4sinagate