Session Fixation
Check List
Methodology
Black Box
Account Take Over
1
2
3
4
5
6
7
Authentication Bypass via Captured Login Responses
1
2
3
4
5
Improper Session Invalidation Allows Account Access After Logout
1
2
3
4
5
6
7
Account Takeover
1
2
3
4
5
6
https://target.com/login
https://target.com/?PHPSESSID=attacker123
https://target.com/dashboard;jsessionid=attacker1237
8
9
10
11
https://target.com/?PHPSESSID=attacker12312
White Box
Cheat Sheet
Last updated