Pluralsight is not an official partner or accredited training center of EC-Council. Session persistence is a fundamental concept in information systems. On the web, for example, which is dependent on the stateless HTTP protocol, session persistence is a key component of features ranging from shopping carts to the ability to logon. At a lower level on the network tier, the TCP protocol relies on sessions for communication between machines such as a client and a server.
Ethical Hacking: Session Hijacking
Ethical Hacking: Session Hijacking is a 53-lesson 3 hours 28 minutes self-paced course by Pluralsight. Pluralsight is not an official partner or accredited training center of EC-Council.
Course facts
- Lessons
- 53
- Duration
- 3 hours 28 minutes
- Level
- All levels
- Language
- English
- Updated
- Instructor
- Pluralsight
- Price
- Free
The confidentiality and integrity of this communication can be seriously impacted by a session hijacking attack. Learning how to identify these risks is an essential capability for the ethical hacker. Systems are frequently built insecurely and readily expose these flaws. Conversely, the risks are often easy to defend against by implementing simple patterns within the application. This course walks through both the risks and the defenses. This course is part of the Ethical Hacking Series. http://blog.pluralsight.com/learning-path-ethical-hacking
Who teaches Ethical Hacking: Session Hijacking? Pluralsight
Pluralsight is one of the largest enterprise-focused online technology training platforms in the world, founded in 2004 by Aaron Skonnard and acquired by Vista Equity Partners in 2021. The platform has historically been the dominant choice for corporate IT training, with a catalog of over 7,000 courses covering software development, IT operations, security, data, and cloud across virtually every major vendor and open-source platform.
The instructor roster includes Microsoft Regional Directors, AWS / Azure / GCP MVPs, and named experts in essentially every active technology track. Course material is structured for the corporate-training market: each course covers a specific skill at a defined depth, and Pluralsight's role-based learning paths are widely used by enterprises for upskilling engineering teams.
The CourseFlix listing under this source carries 12 Pluralsight courses — a small slice of the broader platform's catalog. Material is paid; Pluralsight itself runs on a monthly / annual subscription on the original platform, with Pluralsight Skills (individual) and Pluralsight Flow (engineering analytics) as the main product lines.
What lessons are included in Ethical Hacking: Session Hijacking?
- Space or K: play or pause
- J: rewind 10 seconds
- L: forward 10 seconds
- Left Arrow: rewind 5 seconds
- Right Arrow: forward 5 seconds
- Up Arrow: volume up
- Down Arrow: volume down
- M: mute or unmute
- F: toggle fullscreen
- T: toggle theater mode
- I: toggle mini player
- 0 to 9: seek to 0 to 90 percent of the video
- Shift plus N: next video
- Shift plus P: previous video
| # | Lesson Title | Duration |
|---|---|---|
| 1 | Overview | 02:28 |
| 2 | What Is Session Hijacking? | 01:44 |
| 3 | Types of Session Hijacking | 02:59 |
| 4 | Attack Vectors | 03:41 |
| 5 | The Impact of Session Hijacking | 03:27 |
| 6 | Session Hijacking and the OWASP Top 10 | 02:45 |
| 7 | Summary | 01:31 |
| 8 | Overview | 01:44 |
| 9 | The Stateless Nature of HTTP | 02:53 |
| 10 | Persisting State Over HTTP | 05:46 |
| 11 | Session Persistence in Cookies | 08:50 |
| 12 | Session Persistence in the URL | 06:34 |
| 13 | Session Persistence in Hidden Form Fields | 03:22 |
| 14 | Summary | 02:37 |
| 15 | Overview | 02:19 |
| 16 | Hijacking Cookies with Cross Site Scripting | 09:51 |
| 17 | Exposed Cookie Based Session IDs in Logs | 03:48 |
| 18 | Exposed URL Based Session IDs in Logs | 02:52 |
| 19 | Leaking URL Persisted Sessions in the Referrer | 03:57 |
| 20 | Session Sniffing | 05:33 |
| 21 | Session Fixation | 06:41 |
| 22 | Brute Forcing Session IDs | 04:06 |
| 23 | Session Donation | 05:11 |
| 24 | Summary | 03:04 |
| 25 | Overview | 03:05 |
| 26 | Understanding TCP | 09:00 |
| 27 | Reviewing the Three-way Handshake in Wireshark | 05:23 |
| 28 | Generation and Predictability of TCP Sequence Numbers | 04:31 |
| 29 | Blind Hijacking | 02:29 |
| 30 | Man in the Middle Session Sniffing | 01:58 |
| 31 | IP Spoofing | 01:48 |
| 32 | UDP Hijacking | 02:20 |
| 33 | Man in the Browser Attacks | 02:48 |
| 34 | Network Level Session Hijacking in the Wild | 01:27 |
| 35 | Summary | 02:09 |
| 36 | Overview | 02:13 |
| 37 | Use Strong Session IDs | 03:19 |
| 38 | Keep Session IDs Out of the URL | 02:40 |
| 39 | Don’t Reuse Session ID for Auth | 06:34 |
| 40 | Always Flag Session ID Cookies as HTTP Only | 04:04 |
| 41 | Use Transport Layer Security | 04:43 |
| 42 | Always Flag Session ID Cookies as Secure | 05:39 |
| 43 | Session Expiration and Using Session Cookies | 05:59 |
| 44 | Consider Disabling Sliding Sessions | 03:10 |
| 45 | Encourage Users to Log Out | 02:30 |
| 46 | Re-authenticate Before Key Actions | 01:54 |
| 47 | Summary | 03:16 |
| 48 | Overview | 02:00 |
| 49 | Manipulating Session IDs with OWASP ZAP | 05:04 |
| 50 | Testing Session Token Strength with Burp Suite | 09:48 |
| 51 | Dynamic Analysis Testing with NetSparker | 04:39 |
| 52 | Other Tools | 03:53 |
| 53 | Summary | 02:05 |
What courses are similar to Ethical Hacking: Session Hijacking?
Updated 3y agoThe Complete Cyber Security Course : Hackers Exposed!
By: UdemyLearn a practical skill-set in defeating all online threats, including - advanced hackers, trackers, malware, zero days, exploit kits, cybercriminals and more.12h 6m5/5
Updated 2mo agoThe AI for Ethical Hacking and Cybersecurity Bootcamp
By: Zero To MasteryA practical course on AI in ethical hacking and cybersecurity will help you master automation analysis, SOC enhancement, and modern protection methods.8h 18m5/5
Updated 2y agoBug Bounty - An Advanced Guide to Finding Good Bugs
By: UdemyBug bounties are evolving year after year and thousands of infosec enthuasiasts are looking to join the boat. Having a great place on that boat requires dedicat10h
Updated 1y agoAdvanced Ethical Hacking Bootcamp: Network Hacking & Security
By: Zero To MasteryElevate your ethical hacking skills to a new level by mastering network exploitation techniques - from Man-in-the-Middle attacks and DNS spoofing to router.7h 30m
UpdatedWeb security: Injection Attacks with Java & Spring Boot
By: UdemyHands-on Java and Spring Boot security course covering SQL, NoSQL, LDAP, log, and CSV injection attacks, plus defense-in-depth fixes.8h 44m
More courses by Pluralsight
UpdatedRedux Saga
Learn Redux Saga by building a shopping cart app, covering effects, channels, error handling, and testing async flows with confidence.2h 54m
UpdatedAdvanced Branching and Looping in GO
Master Go's for loops, if/else, and switch statements through real programs and business-focused mini-projects, not just syntax.1h 14m
Updated 2y ago.NET Logging Done Right: An Opinionated Approach Using Serilog
Establishing a foundational framework for logging can save hours in troubleshooting and provide valuable insights to both utilization and performance within all5h 2m
Updated 2y agoBuilding Your First App with Spring Boot and Angular
Spring Boot and Angular have forever changed how web applications are built. Understanding how they work is essential for any full-stack developer. In this cour2h 22m5/5
Updated 2y agoAngular NgRx: Getting Started
At the core of state management in Angular is a thorough knowledge of the Redux pattern and the NgRx library. NgRx is a powerful library for organizing and mana4h 5m
UpdatedIntroduction to SVN
An introduction to Subversion (SVN), covering the fundamentals of this version control system for managing source code changes.2h 56m