Web Security: Common Vulnerabilities And Their Mitigation - Session hijacking using session fixation

Interactive Video
•
Information Technology (IT), Architecture
•
University
•
Hard
Quizizz Content
FREE Resource
Read more
7 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What is the primary goal of session fixation?
To delete a user's session ID
To steal a user's session ID
To set a user's session ID to a known value
To encrypt a user's session ID
2.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
How does untrustedbank.com become vulnerable to session fixation?
By generating new session IDs for each login
By accepting session IDs only from cookies
By accepting any session ID specified by the user
By using encrypted session IDs
3.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What action does the attacker take to exploit the session fixation vulnerability in untrustedbank.com?
Sends a phishing email with a fixated session ID link
Hacks into the bank's server
Steals the victim's password
Uses a brute force attack
4.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Why are server-generated session IDs not a complete solution to session fixation?
Attackers can still use their own server-generated IDs
They are always encrypted
They require user consent
They are too complex to implement
5.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What is a cross sub-domain cookie?
A cookie that is encrypted
A cookie that cannot be accessed by sub-domains
A cookie set by a sub-domain on the main domain
A cookie set by the main domain
6.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
How can an attacker exploit cross sub-domain cookies?
By using cookies only from the main domain
By setting a cookie on a trusted site through an untrusted sub-domain
By deleting all cookies from the browser
By encrypting the cookies
7.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What should a trusted site avoid to prevent session fixation via cross sub-domain cookies?
Allowing third-party sub-domains to set cookies
Using encrypted session IDs
Generating new session IDs for each login
Accepting session IDs only from query strings
Similar Resources on Wayground
8 questions
Learn JMeter from Scratch on Live Applications - Performance Testin - Identifying and Analyzing Correlation

Interactive video
•
University
3 questions
Web Security: Common Vulnerabilities And Their Mitigation - Session hijacking counter measures

Interactive video
•
University
6 questions
The Complete Guide to ASP.NET Core MVC (.NET 5) - Configure Session in the Project

Interactive video
•
University
2 questions
Web Security: Common Vulnerabilities And Their Mitigation - Session hijacking - count the ways

Interactive video
•
University
2 questions
Web Security: Common Vulnerabilities And Their Mitigation - Session ids using hidden form fields and cookies

Interactive video
•
University
6 questions
Web Security: Common Vulnerabilities And Their Mitigation - Session hijacking counter measures

Interactive video
•
University
6 questions
Broken Authentication

Interactive video
•
University
2 questions
Fundamentals of Secure Software - Web Sessions

Interactive video
•
University
Popular Resources on Wayground
18 questions
Writing Launch Day 1

Lesson
•
3rd Grade
11 questions
Hallway & Bathroom Expectations

Quiz
•
6th - 8th Grade
11 questions
Standard Response Protocol

Quiz
•
6th - 8th Grade
40 questions
Algebra Review Topics

Quiz
•
9th - 12th Grade
4 questions
Exit Ticket 7/29

Quiz
•
8th Grade
10 questions
Lab Safety Procedures and Guidelines

Interactive video
•
6th - 10th Grade
19 questions
Handbook Overview

Lesson
•
9th - 12th Grade
20 questions
Subject-Verb Agreement

Quiz
•
9th Grade