Overview
Tokens can be lifted through XSS, network sniffing, malware or fixation, then replayed from anywhere in the world.\nIf the token never rotates and carries no binding, the legitimate user may never notice the duplicate session.\nControls are HttpOnly and Secure cookie flags, short lifetimes, rotation on privilege change, and IP or user-agent anomaly alerts.
Indicators of Compromise
Signals that suggest this is present on a system.
- One session token seen from two distant geographies
- Cookies lacking HttpOnly or Secure
- Sessions surviving password changes
Controls that stop it
-
Encode Output Contextually
Escape data at the moment it is rendered, using the encoding that matches its context: HTML body, HTML attribute, JavaScript, URL or CSS. Combine this with a Content-Security-Policy that forbids inline script, so a missed escape degrades to a broken element instead of code execution.