Session Hijacking

Check List

Methodology

Black Box

Session Fixation – Authentication Bypass

1

There is only one account in different browsers chrome and firefox

2

For example www.example.com I will sign up for one account that is the Chrome browser I filled the details first and last name, password, and confirm password, city, country, phone number, etc and log in now

3

www.example.com same account is created in the firefox browser and I filled the details the same as chrome browser just like as a first and last name, password, and confirm password, city, country, phone number, etc and log in now.

4

Both login into different browsers and I will change for a one-account that is chrome browser that is first and last name, phone number, and change password

5

Changed successfully in a chrome browser and just log out then moves another browser that is firefox and just Refresh the page and I have seen now changes successfully and it's like a boom


White Box

Cheat Sheet

Last updated