Ethical › Module 11 › Lesson 5
Quiz — Session Hijacking
10 APPLY questions on tokens and cookie flags.
Opening
Session hijacking — Module Quiz
Ten APPLY items on the sentences this module refused to collapse: a session token is the “already logged in” secret (cookie or bearer, not a URL); possession often equals identity until expiry or server-side revoke; leak paths are named — XSS without HttpOnly, cleartext without HTTPS/Secure, missing SameSite, ids that survive login, unlocked glass — not a hijack PoC; the shipping list is Secure, HttpOnly, SameSite, short TTL, rotate at login, revoke on logout and password change; the authorized lab is HOST hardcoded 127.0.0.1 (or DevTools on an app YOU own), YOUR Set-Cookie flags in $HOME/cyberlium-lab/ceh-cookie-flags.txt chmod 600. Cyberlium’s artifacts are $HOME/cyberlium-lab notes (session-token, session-stolen-concepts, cookie-flags, ceh-cookie-flags) chmod 600. Stolen cookies, classmate replay, café Wireshark, live XSS, BeEF, CSRF against a shop you do not own, and 0.0.0.0 teaching servers are all failing answers even when they look “more CEH.” This path is original Cyberlium teaching mapped to the CEH v13 session-hijacking domain — not official EC-Council training, not a certification, not exam dumps. Wrong answers still teach. Empty ethics lines fail. Next after this quiz is Firewalls as Policy, Not Magic: Module 12 talks allow/deny and stateful inspection so you can build defenses — not a bypass cookbook.
Knowledge Check
APPLY: A teammate pastes a live shop Cookie header into Discord and wants you to import it in DevTools as “CEH session hijacking.” What is a session token here, and what do you do?
Multiple choice
Knowledge Check
APPLY: True or False: If loopback is boring, the ethical homework is intercepting café users and replaying a stranger’s cookie because Module 11 is “session hijacking.”
True or False
Knowledge Check
APPLY: curl -sI http://127.0.0.1:8766/ after a listener YOU started shows Set-Cookie with HttpOnly and SameSite. What did you practice, and what is not required?
Multiple choice
Knowledge Check
APPLY: Why does this course call a non-HttpOnly session cookie a finding, and where must that observation live?
Multiple choice
Knowledge Check
APPLY: Select statements that match the cookie shipping list (not a steal kit). (Select 2)
Select all that apply
Knowledge Check
APPLY: An allowed observer watches leftover HTTP to a login YOU run. What should they get, and what is the fix?
Multiple choice
Knowledge Check
APPLY: True or False: SameSite replaces HTTPS, so you may skip Secure and XSS a live search box to prove HttpOnly is optional.
True or False
Knowledge Check
APPLY: You finished the cookie lab. Which cleanup and note pairing is required before the quiz badge?
Multiple choice
Knowledge Check
APPLY: A blog titled with a cert acronym publishes “session hijacking commands” aimed at café Wi-Fi, BeEF, and cookie replay. What does Cyberlium Module 11 tell you?
Multiple choice
Knowledge Check
APPLY: You carry Module 11 into Module 12. Which pairing is true, and what opens after this quiz?
Multiple choice
Knowledge Check
APPLY: curl of http://192.168.0.1/ shows a home router login (TP-Link / Netgear / Huawei / "Router Admin"). Is that DEMO in scope as a hacking target?
Multiple choice
Answer all 11 knowledge checks to continue. (0/11 answered)