Sitemap

Our best price of the year.

Get 20% off new memberships for a limited time.now.

InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties and CTFs to vulnhub machines, hardware challenges and real life encounters. Subscribe to our weekly newsletter for the coolest infosec updates: https://weekly.infosecwriteups.com/

A Practical Guide to Authentication and Session Management Vulnerabilities

A step-by-step breakdown of the most common Session Management Vulnerabilities

7 min readJust now

--

Press enter or click to view image in full size

Introduction

Modern applications rely heavily on sessions, tokens and identity checks. When these controls aren’t implemented correctly, attackers can bypass restrictions or take over accounts with little effort. In this guide, I’ll walk you through a checklist of all session-related issues, how to test for them and what their impact can look like. It’s a straightforward way to confirm whether an application’s session handling is actually secure.

1. Old Session Does Not Expire After Password Change

Description: When a user changes their password, all existing active sessions (on other devices or browsers) should generally be invalidated.

Steps to Reproduce:

  1. Create an account on the target site.
  2. Log in to the account on two different browsers (e.g., Chrome and Firefox/Incognito).
  3. On Chrome, navigate to settings and change your password.
  4. Once the password change is successful, go to the Firefox window (where the old session is active)…

--

--

InfoSec Write-ups

Published in InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties and CTFs to vulnhub machines, hardware challenges and real life encounters. Subscribe to our weekly newsletter for the coolest infosec updates: https://weekly.infosecwriteups.com/

coffinxp

Written by coffinxp

Helping organizations stay secure through Bug Hunting, OSINT and Security Research | Sharing knowledge as a Content Creator

No responses yet