Skip to content

What it blocks

Session attacks

Someone tries to force a visitor onto a session they control.

What it is

A request that tries to set a visitor's session id from outside the site.

  • A session id passed in a link from another website

Why it matters

If a visitor signs in on a session the attacker chose, the attacker is signed in as them.

When it stops a real visitor

Some older sites pass the session in the address on purpose. Mark the request as real if yours does.

All 3 rules in this kind, as the rule set names them

For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.

  • 943100Possible Session Fixation Attack: Setting Cookie Values in HTML
  • 943110Possible Session Fixation Attack: SessionID Parameter Name with Off-Domain Referer
  • 943120Possible Session Fixation Attack: SessionID Parameter Name with No Referer