Detailedlikelihood: Highseverity: HighDraft
CAPEC-102Session Sidejacking
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
Session sidejacking takes advantage of an unencrypted communication channel between a victim and target system. The attacker sniffs traffic on a network looking for session tokens in unencrypted traffic. Once a session token is captured, the attacker performs malicious actions by using the stolen token with the targeted application to impersonate the victim. This attack is a specific method of session hijacking, which is exploiting a valid session token to gain unauthorized access to a target system or information. Other methods to perform a session hijacking are session fixation, cross-site scripting, or compromising a user or server machine and stealing the session token.
Related weaknesses· 5
Related attack patterns· 1
Exploits5
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Sensitive Cookie in HTTPS Session Without 'Secure' Attributecwe-614 | 100% | live |
| Weakness | Unprotected Transport of Credentialscwe-523 | 100% | live |
| Weakness | Insufficiently Protected Credentialscwe-522 | 100% | live |
| Weakness | Cleartext Transmission of Sensitive Informationcwe-319 | 100% | live |
| Weakness | Authentication Bypass by Capture-replaycwe-294 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.