Results 1 to 3 of 3

Thread: What Is Session Hijacking and is it Possible?

  1. #1
    Join Date
    Dec 2008
    Posts
    69

    What Is Session Hijacking and is it Possible?

    Hello Friends,

    I have yahoo account and I access my account mostly from the cyber but i am not sure about the security related to my yahoo account because it may possible to retrieve all the information about my account by session hijacking.

    so please suggest me how session Hijacking has been done and how to save my account details while accessing from the public places.

    Thank for all of those who helps...

  2. #2
    Join Date
    Mar 2008
    Posts
    151

    Re: What Is Session Hijacking and is it Possible?

    Hello,
    Here i have provided what the session hijacking is and how a hacker may hijack the session.

    The term session hijacking refers to the exploitation of a valid computer session - sometimes also called a session key - to gain unauthorized access to information or services in a computer system.

    In particular, it is used to refer to the theft of a magic cookie used to authenticate a user to a remote server.It has particular relevance to web developers, as the HTTP cookies used to maintain a session on many web sites can be stolen easily by an attacker using an intermediary computer or with access to the cookies saved on the victim's computer.

    Many Web sites allow users to create and manage their own accounts, Logging in using a username and password (which may or may not be encrypted during transit) or other authentication method. In order that the user does not have to re-enter their username and password on every page to maintain their session, many Web sites use session cookies: a token of information issued by the server and returned by the user's web browser to confirm its identity .

    If an attacker is able to steal this cookie, they can make requests as if they themselves were the genuine user, gaining access to privileged information or changing data. If this cookie is a persistent cookies, then the impersonation can continue for a considerable period of time. Of course, session hijacking is not limited to the web, any protocol in which state is maintained using a key passed between two parties is vulnerable, especially if it's not encrypted.

  3. #3
    Join Date
    Oct 2008
    Posts
    107

    Re: What Is Session Hijacking and is it Possible?

    Only thing left with your hand is to clear all the cookies and private data from the internet browser of the computer you used in the cyber cafe. But i suppose you cant do anything if your account information has been hijaced during the running session.

    otherwise all the necessary thing that has been well described by the SAMRA above.

Similar Threads

  1. How to protect your system from Session Hijacking
    By kattman in forum Guides & Tutorials
    Replies: 1
    Last Post: 30-06-2012, 04:14 PM
  2. Replies: 4
    Last Post: 17-01-2011, 11:14 AM
  3. Replies: 4
    Last Post: 24-12-2010, 07:58 AM
  4. Bing Hijacking
    By Chestery in forum Technology & Internet
    Replies: 4
    Last Post: 11-09-2010, 06:12 PM
  5. Prevent PHP Form Hijacking
    By Henryosa in forum Software Development
    Replies: 5
    Last Post: 13-01-2010, 11:40 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,940,333.46576 seconds with 17 queries