Session Fixation

Detect and exploit session fixation (WSTG-SESS-01, WSTG-SESS-03) and session exposure (WSTG-SESS-04) by testing whether the server issues a new session token post-authentication, whether pre-login tokens remain valid after login, and whether session IDs are transmitted over HTTP or included in GET parameters. Analyze token randomness via Burp Sequencer. Test JSESSIONID, ASP.NET Forms Auth cookies. Tools: OWASP ZAP, Burp Suite Repeater/Sequencer, JHijack.

ShulkwiSEC Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/session-fixation commit 6eeeb39e95

Frequently asked questions

npx skillmds@latest add shulkwisec/session-fixation