Ravindra BagaleCourses & study guides

41. Session Hijacking – Tokens, Cookies and Defence

Chala mitrano, Chapter 40 madhe availability baghitla – aata session hijacking. HTTP by default stateless aahe. Login zala ki browser la session token / cookie deto – he token = tumchi identity for that visit. Red jar he token chori kela / guess kela / fix kela, tar website Rani samajte – actually Shahrukh (attacker) boltoy. CIA madhe he confidentiality (गोपनीयता) + integrity (अखंडता) of identity. Ghabru naka – aapan OWN host-only PHP lab var demo; internet Wi-Fi / third-party sites nahi. He khup important aahe, lakshat theva!

What you will learn in this chapter

  • What a session is; why hijacking breaks identity trust
  • Cookie theft on insecure transit (HTTP vs HTTPS; Secure / HttpOnly / SameSite)
  • Session fixation and predictable session IDs
  • XSS → cookie steal path (high-level) + CSP / encoding / HttpOnly defence
  • Network sniffing of sessions (Wireshark/tcpdump concepts; HSTS)
  • Application-level hijack: token in URL, CSRF vs session, JWT pitfalls (concepts)
  • Detection: concurrent sessions, UA/IP anomalies, SIEM signals
  • Defence checklist: regenerate on login, short TTL, logout invalidate, MFA, WAF
  • Lab-safe PHP cookie demo on OWN nginx/Apache + ethics / IT Act
  • Project Build-Hack-Fix for Raja-Rani / Sahyadri Traders login session

Lab scope

Practice only against systems you own in host-only / isolated lab (Kali 192.168.56.10, Metasploitable 192.168.56.20, your own PHP/nginx/Apache lab VM). Cookie theft, fixation, and replay demos = OWN PHP app only. Never sniff open café Wi-Fi for strangers' cookies, never steal sessions from live shops, never XSS-inject third-party sites. Tools like Burp / curl / Wireshark stay pointed at host-only IPs. IT Act sections such as 43 and 66 apply if you access others' accounts without authority (verify current text). Lab = learn defence. Production = protect sessions.

Concepts in this chapter

  1. 41.1What Is a Session – Why Hijacking Matters
  2. 41.2Cookie Theft and Insecure Transit
  3. 41.3Session Fixation and Predictable IDs
  4. 41.4XSS Path to Session Cookies – Defence First
  5. 41.5Network Sniffing of Sessions – Host-Only Concepts
  6. 41.6Application-Level Hijack – URL Tokens, CSRF, JWT Concepts
  7. 41.7Detection – Logs, Concurrent Sessions, SIEM Signals
  8. 41.8Defence Hardening Checklist
  9. 41.9Lab-Safe PHP Cookie Demo + Ethics / IT Act
  10. 41.10Putting It Together – Purple Team Mindset

The chapter recap is at the end of the last concept page.