41. Session Hijacking – Tokens, Cookies and Defence
Chala mitrano, Chapter 40 madhe availability baghitla – aata session hijacking. HTTP by default stateless aahe. Login zala ki browser la session token / cookie deto – he token = tumchi identity for that visit. Red jar he token chori kela / guess kela / fix kela, tar website Rani samajte – actually Shahrukh (attacker) boltoy. CIA madhe he confidentiality (गोपनीयता) + integrity (अखंडता) of identity. Ghabru naka – aapan OWN host-only PHP lab var demo; internet Wi-Fi / third-party sites nahi. He khup important aahe, lakshat theva!
What you will learn in this chapter
- What a session is; why hijacking breaks identity trust
- Cookie theft on insecure transit (HTTP vs HTTPS; Secure / HttpOnly / SameSite)
- Session fixation and predictable session IDs
- XSS → cookie steal path (high-level) + CSP / encoding / HttpOnly defence
- Network sniffing of sessions (Wireshark/tcpdump concepts; HSTS)
- Application-level hijack: token in URL, CSRF vs session, JWT pitfalls (concepts)
- Detection: concurrent sessions, UA/IP anomalies, SIEM signals
- Defence checklist: regenerate on login, short TTL, logout invalidate, MFA, WAF
- Lab-safe PHP cookie demo on OWN nginx/Apache + ethics / IT Act
- Project Build-Hack-Fix for Raja-Rani / Sahyadri Traders login session
Lab scope
Practice only against systems you own in host-only / isolated lab (Kali 192.168.56.10, Metasploitable 192.168.56.20, your own PHP/nginx/Apache lab VM). Cookie theft, fixation, and replay demos = OWN PHP app only. Never sniff open café Wi-Fi for strangers' cookies, never steal sessions from live shops, never XSS-inject third-party sites. Tools like Burp / curl / Wireshark stay pointed at host-only IPs. IT Act sections such as 43 and 66 apply if you access others' accounts without authority (verify current text). Lab = learn defence. Production = protect sessions.
Concepts in this chapter
- 41.1What Is a Session – Why Hijacking Matters
- 41.2Cookie Theft and Insecure Transit
- 41.3Session Fixation and Predictable IDs
- 41.4XSS Path to Session Cookies – Defence First
- 41.5Network Sniffing of Sessions – Host-Only Concepts
- 41.6Application-Level Hijack – URL Tokens, CSRF, JWT Concepts
- 41.7Detection – Logs, Concurrent Sessions, SIEM Signals
- 41.8Defence Hardening Checklist
- 41.9Lab-Safe PHP Cookie Demo + Ethics / IT Act
- 41.10Putting It Together – Purple Team Mindset
The chapter recap is at the end of the last concept page.