Umbra Wiki attack-pattern attack-pattern/CAPEC-593
Back to wiki

CAPEC-593 — Session Hijacking

provenance: imported · ATT&CK: T1185 T1550.001 T1563 · CWE: CWE-287

CAPEC-593: Session Hijacking

MITRE CAPEC attack pattern

Status Stable
Typical severity Very High
Likelihood of attack High
Catalogue CAPEC 3.9 (2023-01-24)

Description

This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adversary is able to steal or manipulate an active session and use it to gain unathorized access to the application.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-287

ATT&CK techniques: T1185, T1550.001, T1563

Prerequisites

  • An application that leverages sessions to perform authentication.

Skills required

  • Low: Exploiting a poorly protected identity token is a well understood attack with many helpful resources available.

Consequences

  • Confidentiality, Integrity, Availability: Gain Privileges

Mitigations

  • Properly encrypt and sign identity tokens in transit, and use industry standard session key generation mechanisms that utilize high amount of entropy to generate the session key. Many standard web and application servers will perform this task on your behalf. Utilize a session timeout for all sessions. If the user does not explicitly logout, terminate their session after this period of inactivity. If the user logs back in then a new session key should be generated.

Source