Cookies and how to bake them: what they are for, associated risks, and what session hijacking has to do with it
ID: 94b6e47b-ec90-5b35-a1c3-5e40d66badf6
STIX ID: report--94b6e47b-ec90-5b35-a1c3-5e40d66badf6
Feed Name: Securelist by Kaspersky
This article explains how cookies and Session IDs work, categorizes cookie types (by storage time, source, importance, and special forms like supercookies/evercookies), describes session-hijacking methods (session sniffing, XSS, session fixation, CSRF, MitM, predictable IDs, cookie tossing), and provides concrete mitigation advice for developers (HTTPS, HSTS, Secure/HttpOnly/SameSite flags, CSRF tokens, regenerating session IDs, __Host- prefix, subdomain hygiene) and users (use HTTPS, avoid suspicious links, clear cookies, use 2FA, use VPN on public Wi‑Fi).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
