Session Fixation
π Stages of Testing for Session Fixation Vulnerabilities
- π οΈ Testing for Session Fixation
http://example.com/?redirect_uri=/complete.html&token=IControlThisCookie
π Example Code Analysis<?php if (!isset($_GET["token"])) { session_start(); header("Location: /?redirect_uri=/complete.html&token=" . session_id()); } else { setcookie("PHPSESSID", $_GET["token"]); } ?>
Last updated