logo

Cookies and how to bake them: what they are for, associated risks, and what session hijacking has to do with it

ID: 94b6e47b-ec90-5b35-a1c3-5e40d66badf6

STIX ID: report--94b6e47b-ec90-5b35-a1c3-5e40d66badf6

Feed Name: Securelist by Kaspersky

Date Published: 2025-09-02

Date Updated: 2026-04-29

Author: Anna Larkina, Natalya Zakuskina

...
...

This article explains how cookies and Session IDs work, categorizes cookie types (by storage time, source, importance, and special forms like supercookies/evercookies), describes session-hijacking methods (session sniffing, XSS, session fixation, CSRF, MitM, predictable IDs, cookie tossing), and provides concrete mitigation advice for developers (HTTPS, HSTS, Secure/HttpOnly/SameSite flags, CSRF tokens, regenerating session IDs, __Host- prefix, subdomain hygiene) and users (use HTTPS, avoid suspicious links, clear cookies, use 2FA, use VPN on public Wi‑Fi).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.