Session Hijacking
Cookies and tokens as identity — HTTPS, HttpOnly, SameSite as fixes.
1. What a Session Token Is
The browser’s “already logged in” string is a secret.
15 min
+40 XP
2. How Sessions Get Stolen (Concepts)
XSS, open Wi-Fi, missing flags — not a hijack PoC.
15 min
+40 XP
3. Cookie Flags and Logout Hygiene
Secure, HttpOnly, SameSite, short TTL, revoke on password change.
15 min
+40 XP
4. Lab — Inspect Cookie Flags on a Site You Own
DevTools on YOUR app or a local page you wrote — not intercepting others.
25 min
+40 XP
5. Quiz — Session Hijacking
10 APPLY questions on tokens and cookie flags.
10 min
+40 XP