Ethical Hacking: Session Hijacking
1h 14mIntermediate2021-01-07
Authors

Malcolm Shore
Cybersecurity Expert, Former Director of GCSB
Course details
One of the most sophisticated forms of cyberattacks is session hijacking. Hackers take over network, web, or service sessions—the valid interactions of unsuspecting users—in order to gain unauthorized access to data and systems and attack an organization from the inside. The root failure is weaknesses in common protocols. To prevent these attacks, IT security professionals need to know which protocols are vulnerable and how to test their systems for exposure.
This course teaches you what session hijacking is, and how black-hat hackers use it to attack an organization. Learn how TCP, web, and wireless protocols work and how hackers exploit them. Find out how to use built-in Windows and Linux tools, as well as specialized third-party solutions such as Zed Attack Proxy (ZAP) and Cain, to detect and shore up vulnerabilities. Author and cybersecurity expert Malcolm Shore also discusses remote hijacking, which allows hackers to take control of drones or even vehicles.
This course teaches you what session hijacking is, and how black-hat hackers use it to attack an organization. Learn how TCP, web, and wireless protocols work and how hackers exploit them. Find out how to use built-in Windows and Linux tools, as well as specialized third-party solutions such as Zed Attack Proxy (ZAP) and Cain, to detect and shore up vulnerabilities. Author and cybersecurity expert Malcolm Shore also discusses remote hijacking, which allows hackers to take control of drones or even vehicles.
Skills covered
Security TestingLinuxCybersecurityCert PrepOpen Source
Concepts
0. Introduction
- 01 - Understanding session hijacking
- 02 - What you should know before watching this course
- 03 - Disclaimer
1. Network Session Hijacking
- 04 - Understanding TCP sequence numbers
- 05 - Hijacking a Telnet session
- 06 - Real-world hijacks
2. Web Session Hijacking
- 07 - Understanding web sessions
- 08 - Understanding WebSockets
- 09 - Banking on Zero
- 10 - Hijacking sessions using man-in-the-browser
- 11 - Intercepting sessions through man-in-the-middle
- 12 - Stripping SSL to downgrade the session
- 13 - Hijacking an HTTP session through cookies
- 14 - Using Subterfuge to hijack sessions through ARP poisoning
- 15 - Using Webscarab-NG as a web proxy
3. Additional Tools
- 16 - Using Zed Attack Proxy (ZAP)
- 17 - Using Cain
4. Service Hijacking
- 18 - Hijacking SSH sessions
- 19 - DNS hijacking
- 20 - Cloud hijacking
5. Hijacking in the Physical World
- 21 - Going physical - Hijacking cars and drones
- 22 - Getting more physical with drones
Conclusion
- 23 - Next steps