What type of session hijacking attack is shown in the exhibit?
A.
Cross-site scripting Attack
B.
SQL Injection Attack
C.
Token sniffing Attack
D.
Session Fixation Attack
What type of session hijacking attack is shown in the exhibit?
A.
Cross-site scripting Attack
B.
SQL Injection Attack
C.
Token sniffing Attack
D.
Session Fixation Attack
A is the Ans.
Ans: D
Session Fixation – Social engineering is involved in this attack.
This photo is fairly misleading. Step 1 is the attacker logging into the vulnerable web application. The attacker then sends this ID to the victim who logs into the web application. Session ID is known to the attacker, just reload the browser. Hence the term fixation.
100% D
2ez4sinagate