CAPEC™ 593: Session Hijacking
Description
This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adversary is able to steal or manipulate an active session and use it to gain unathorized access to the application.
Source: CAPEC™ 593
Related ASVS Requirements
ASVS (5.0): 10.4.8, 12.1.1, 12.2.1, 12.3.1, 12.3.3, 14.2.1, 14.2.2, 16.2.5, 16.5.1, 3.1.1, 3.3.1, 3.3.2, 3.3.3, 3.3.4, 3.4.1, 3.7.4, 7.1.1, 7.1.2, 7.1.3, 7.2.4, 7.3.1, 7.3.2, 7.4.1, 7.4.2, 7.4.3, 7.4.4, 7.4.5, 7.5.2, 7.6.1, 8.1.3, 8.1.4, 8.2.4, 8.3.2