Session attacks
Someone tries to force a visitor onto a session they control.
What it is
A request that tries to set a visitor's session id from outside the site.
- A session id passed in a link from another website
Why it matters
If a visitor signs in on a session the attacker chose, the attacker is signed in as them.
When it stops a real visitor
Some older sites pass the session in the address on purpose. Mark the request as real if yours does.
All 3 rules in this kind, as the rule set names them
For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.
- 943100Possible Session Fixation Attack: Setting Cookie Values in HTML
- 943110Possible Session Fixation Attack: SessionID Parameter Name with Off-Domain Referer
- 943120Possible Session Fixation Attack: SessionID Parameter Name with No Referer