Pluralsight is not an official partner or accredited training center of EC-Council. Session persistence is a fundamental concept in information systems. On the web, for example, which is dependent on the stateless HTTP protocol, session persistence is a key component of features ranging from shopping carts to the ability to logon. At a lower level on the network tier, the TCP protocol relies on sessions for communication between machines such as a client and a server.
Ethical Hacking: Session Hijacking
Ethical Hacking: Session Hijacking is a 53-lesson 3 hours 28 minutes self-paced course by Pluralsight. Pluralsight is not an official partner or accredited training center of EC-Council.
Course facts
- Lessons
- 53
- Duration
- 3 hours 28 minutes
- Level
- All levels
- Language
- English
- Updated
- Instructor
- Pluralsight
- Price
- Free
The confidentiality and integrity of this communication can be seriously impacted by a session hijacking attack. Learning how to identify these risks is an essential capability for the ethical hacker. Systems are frequently built insecurely and readily expose these flaws. Conversely, the risks are often easy to defend against by implementing simple patterns within the application. This course walks through both the risks and the defenses. This course is part of the Ethical Hacking Series. http://blog.pluralsight.com/learning-path-ethical-hacking
Who teaches Ethical Hacking: Session Hijacking? Pluralsight
Pluralsight is one of the largest enterprise-focused online technology training platforms in the world, founded in 2004 by Aaron Skonnard and acquired by Vista Equity Partners in 2021. The platform has historically been the dominant choice for corporate IT training, with a catalog of over 7,000 courses covering software development, IT operations, security, data, and cloud across virtually every major vendor and open-source platform.
The instructor roster includes Microsoft Regional Directors, AWS / Azure / GCP MVPs, and named experts in essentially every active technology track. Course material is structured for the corporate-training market: each course covers a specific skill at a defined depth, and Pluralsight's role-based learning paths are widely used by enterprises for upskilling engineering teams.
The CourseFlix listing under this source carries 12 Pluralsight courses — a small slice of the broader platform's catalog. Material is paid; Pluralsight itself runs on a monthly / annual subscription on the original platform, with Pluralsight Skills (individual) and Pluralsight Flow (engineering analytics) as the main product lines.
What lessons are included in Ethical Hacking: Session Hijacking?
- Space or K: play or pause
- J: rewind 10 seconds
- L: forward 10 seconds
- Left Arrow: rewind 5 seconds
- Right Arrow: forward 5 seconds
- Up Arrow: volume up
- Down Arrow: volume down
- M: mute or unmute
- F: toggle fullscreen
- T: toggle theater mode
- I: toggle mini player
- 0 to 9: seek to 0 to 90 percent of the video
- Shift plus N: next video
- Shift plus P: previous video
| # | Lesson Title | Duration |
|---|---|---|
| 1 | Overview | 02:28 |
| 2 | What Is Session Hijacking? | 01:44 |
| 3 | Types of Session Hijacking | 02:59 |
| 4 | Attack Vectors | 03:41 |
| 5 | The Impact of Session Hijacking | 03:27 |
| 6 | Session Hijacking and the OWASP Top 10 | 02:45 |
| 7 | Summary | 01:31 |
| 8 | Overview | 01:44 |
| 9 | The Stateless Nature of HTTP | 02:53 |
| 10 | Persisting State Over HTTP | 05:46 |
| 11 | Session Persistence in Cookies | 08:50 |
| 12 | Session Persistence in the URL | 06:34 |
| 13 | Session Persistence in Hidden Form Fields | 03:22 |
| 14 | Summary | 02:37 |
| 15 | Overview | 02:19 |
| 16 | Hijacking Cookies with Cross Site Scripting | 09:51 |
| 17 | Exposed Cookie Based Session IDs in Logs | 03:48 |
| 18 | Exposed URL Based Session IDs in Logs | 02:52 |
| 19 | Leaking URL Persisted Sessions in the Referrer | 03:57 |
| 20 | Session Sniffing | 05:33 |
| 21 | Session Fixation | 06:41 |
| 22 | Brute Forcing Session IDs | 04:06 |
| 23 | Session Donation | 05:11 |
| 24 | Summary | 03:04 |
| 25 | Overview | 03:05 |
| 26 | Understanding TCP | 09:00 |
| 27 | Reviewing the Three-way Handshake in Wireshark | 05:23 |
| 28 | Generation and Predictability of TCP Sequence Numbers | 04:31 |
| 29 | Blind Hijacking | 02:29 |
| 30 | Man in the Middle Session Sniffing | 01:58 |
| 31 | IP Spoofing | 01:48 |
| 32 | UDP Hijacking | 02:20 |
| 33 | Man in the Browser Attacks | 02:48 |
| 34 | Network Level Session Hijacking in the Wild | 01:27 |
| 35 | Summary | 02:09 |
| 36 | Overview | 02:13 |
| 37 | Use Strong Session IDs | 03:19 |
| 38 | Keep Session IDs Out of the URL | 02:40 |
| 39 | Don’t Reuse Session ID for Auth | 06:34 |
| 40 | Always Flag Session ID Cookies as HTTP Only | 04:04 |
| 41 | Use Transport Layer Security | 04:43 |
| 42 | Always Flag Session ID Cookies as Secure | 05:39 |
| 43 | Session Expiration and Using Session Cookies | 05:59 |
| 44 | Consider Disabling Sliding Sessions | 03:10 |
| 45 | Encourage Users to Log Out | 02:30 |
| 46 | Re-authenticate Before Key Actions | 01:54 |
| 47 | Summary | 03:16 |
| 48 | Overview | 02:00 |
| 49 | Manipulating Session IDs with OWASP ZAP | 05:04 |
| 50 | Testing Session Token Strength with Burp Suite | 09:48 |
| 51 | Dynamic Analysis Testing with NetSparker | 04:39 |
| 52 | Other Tools | 03:53 |
| 53 | Summary | 02:05 |
What courses are similar to Ethical Hacking: Session Hijacking?
-
Updated 2y agoBug Bounty - An Advanced Guide to Finding Good Bugs
By: UdemyBug bounties are evolving year after year and thousands of infosec enthuasiasts are looking to join the boat. Having a great place on that boat requires dedicat10h -
Updated 1y agoAdvanced Ethical Hacking Bootcamp: Network Hacking & Security
By: Zero To MasteryElevate your ethical hacking skills to a new level by mastering network exploitation techniques - from Man-in-the-Middle attacks and DNS spoofing to router.7h 30m -
Updated 3y agoThe Complete Cyber Security Course : Hackers Exposed!
By: UdemyLearn a practical skill-set in defeating all online threats, including - advanced hackers, trackers, malware, zero days, exploit kits, cybercriminals and more.12h 6m5/5 -
Updated 3y agoWeb security: Injection Attacks with Java & Spring Boot
By: UdemyAre you a Java web developer and want to write secure code? Do you want to learn Ethical hacking and Web application security?8h 44m
More courses by Pluralsight
-
Updated 2y agoRedux Saga
Redux Saga is a fast-growing library with over 9,000 stars on GitHub. It lets you rapidly create asynchronous apps using a new tool called ES6 Generators. In th2h 54m -
Updated 2y agoAdvanced Branching and Looping in GO
GO is a relatively new programming language. In this course, Advanced Branching and Looping in GO, you will gain the ability to effectively use the GO for loop1h 14m -
Updated 2y ago.NET Logging Done Right: An Opinionated Approach Using Serilog
Establishing a foundational framework for logging can save hours in troubleshooting and provide valuable insights to both utilization and performance within all5h 2m -
Updated 2y agoBuilding Your First App with Spring Boot and Angular
Spring Boot and Angular have forever changed how web applications are built. Understanding how they work is essential for any full-stack developer. In this cour2h 22m5/5 -
Updated 2y agoAngular NgRx: Getting Started
At the core of state management in Angular is a thorough knowledge of the Redux pattern and the NgRx library. NgRx is a powerful library for organizing and mana4h 5m -
Updated 3y agoIntroduction to SVN
Take your skills to the next level with courses on the most popular programming languages, developer tools, software practices and application development platf2h 56m