Skip to content
ScopefileGet the app

Module 11Domain 4 of 9Network and Perimeter Hacking

Session hijacking at the application and network layers

Session hijacking means taking over a session that a real user has already opened and authenticated. At the application level that happens through the web token the server trusts; at the network level it happens to a live TCP connection. Sort every Module 11 term into one of those two layers first, then attach the control that removes the weakness it depends on.

Exam
312-50
Domain
4 of 9
Domain weight
24%
This file
~5%
Targets
17

Session attacks by the flaw they exploit

Session ID theft
Someone obtains a valid session token and presents it as their own. It depends on tokens that travel unencrypted, can be read by page script, or leak into URLs and logs.
Session fixation
The victim ends up logging in inside a session whose ID the attacker already knows. It depends on an application that keeps one session ID across authentication.
Session prediction
A valid token is worked out without ever being seen. It depends on IDs built from guessable ingredients instead of a cryptographically secure random source.
Session replay
A token that was valid once is accepted again in a later request. It depends on tokens with long lifetimes and on servers that never check freshness.
Man-in-the-browser
Malware inside the victim's browser alters or rides transactions after a genuine login. It depends on a compromised endpoint, so the fix sits on the device.
TCP (network-level) hijacking
Someone on the network path takes over an established TCP connection by injecting traffic the endpoints accept as part of it. It depends on cleartext protocols and observable connection state.
RST and blind hijacking
Two network-level variants: RST hijacking forges a reset that tears a connection down, and blind hijacking injects data without seeing the replies. Both depend on traffic that carries no integrity check.

Application level against network level

The two halves of Module 11, as blueprint v5.0 names them (checked Oct 11, 2026)
TraitApplication levelNetwork level
What is taken over (differs)The session token a web app issues after loginA live TCP connection between two hosts
Weakness relied on (differs)Token exposure, fixation, weak generation, long lifetimesCleartext transport and observable connection state
Where the attacker must be (differs)Anywhere the token can be read or planted, including the victim's browserOn or next to the network path
What a defender observes (differs)Session IDs in URLs or logs, an ID that survives login, tokens used after logoutFloods of duplicate acknowledgments, resets neither endpoint sent
First-line controls (differs)HTTPS on every page, protective cookie flags, a new ID at login, timeoutsIntegrity-protected channels, switch anti-spoofing features, segmentation
Testing needs written authorizationYesYes

Tinted rows marked ≠: the two differ.

Threat, weakness, first control

Each session attack against the weakness it needs, the control that closes it and the signal to watch
Matrix of six session hijacking classes with the weakness each relies on, the first control that closes it and the signal a defender watches for. Session fixation paired with issuing a new ID at login is highlighted.WeaknessFirst controlWatch forID theftToken exposedHTTPS plus cookieflagsIDs in URLs or logsFixationID kept across loginNew ID at loginPre-login ID stilllivePredictionLow-entropy IDsFramework random IDsBursts of invalid IDsReplayLong-lived tokensShort expiryUse after logoutTCP hijackCleartext transportProtect the channelACK storms, resetsMan-in-browserInfected endpointOut-of-band confirmAltered transactions

What defenders see in logs and traffic

Triage for this module is short. The layer split and the six rows of that matrix carry it; tool rosters are the tail, so recognize the names and spend no evenings on them.

Detection works the same way the definitions do: the evidence tells you the layer before it tells you the attack.

  • Evidence in cookies, tokens and web server logs belongs to the application level. Evidence in packets, acknowledgments and switch alerts belongs to the network level.
  • Session identifiers turning up in URLs, referrer headers or proxy logs mean the token is already exposed to anyone who can read those records.
  • Bursts of requests carrying invalid session identifiers from one source suggest someone probing the ID space, which is a reason to review how IDs are generated.
  • Duplicate acknowledgments piling up, or connections dropped by resets neither endpoint sent, signal interference with a live TCP connection.

Where this module borrows from its neighbors

Network-level hijacking needs a position on the path, and that position usually comes from the interception attacks in Module 8 on sniffing; the switch-level defenses are laid out on layer-2 attacks and their defenses. Spotting hijack attempts on the wire often falls to intrusion detection, and the device roles involved are compared on IDS vs IPS vs firewall. Cross-site scripting and request forgery both touch sessions too, and the three web flaws are set side by side on XSS vs CSRF vs SSRF.

Sessions belong to real people, so an authorized test stays on tester-owned accounts inside the written scope and destroys any token it obtains once the finding is reported.

Make the layer call

Each target describes a session under attack or under repair. Commit to an answer, then read the note under every option, the wrong ones included.

Answered 0/17Hits 0

T-01

A packet capture reveals unsolicited ARP replies mapping an unknown MAC address to the network gateway IP, followed by unencrypted HTTP requests containing a session cookie. The application enforces HTTPS but loads HTTP images. Which attack occurred?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ANothing in the capture points to forged DNS answers, and the cookie leaked through cleartext HTTP rather than through a script injected into the page.
  2. BThe unsolicited ARP replies do fit ARP spoofing, but CSRF makes the victim's browser send forged requests and never discloses the session cookie to the attacker.
  3. CMAC flooding fills a switch's address table with bogus entries, which looks different from targeted ARP replies claiming the gateway's IP address.
  4. DCorrect: Spoofed ARP replies put the attacker in the path, and HTTP-loaded images let a cookie without the Secure attribute travel in cleartext; HSTS and the Secure flag prevent this.
T-02

In Scenario A, an attacker provides a predetermined session identifier before the victim authenticates. In Scenario B, an attacker intercepts an active cookie after the victim's successful authentication. How are these attacks classified?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASupplying a known ID before login is not replay, and taking a live cookie is interception of a real token rather than prediction of an unknown one.
  2. BCorrect: Planting an identifier before authentication is session fixation, while reusing a cookie captured after login is session replay; regenerating the ID at login and binding tokens defeat them.
  3. CNeither scenario forges a cross-site request; fixation abuses a pre-set identifier, and capturing a post-login cookie is session theft rather than CSRF.
  4. DThis reverses the labels: the pre-authentication identifier in Scenario A is the fixation case, while Scenario B takes an already issued token.
T-03

Which attack involves capturing initial protocol handshake data and replaying it later to gain unauthorized access?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APass-the-hash reuses a stolen NTLM password hash to authenticate in Windows environments, rather than retransmitting a recorded handshake.
  2. BSession hijacking takes over an established, active session, typically via a stolen token, instead of replaying recorded handshake data at a later time.
  3. CMan-in-the-browser is malware inside the victim's browser that alters pages and transactions in real time, not a recording replayed later.
  4. DCorrect: A replay attack retransmits captured valid traffic such as an authentication exchange; nonces, timestamps and session-unique challenges defeat it.
T-04

A web application enforces strict TLS across all communications. However, authenticated user sessions are still being hijacked. Which vulnerability is MOST likely allowing this compromise?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AProperly implemented pinning makes interception harder, and strict TLS throughout would surface certificate errors rather than silently enable hijacking.
  2. BCorrect: Cross-site scripting runs in the victim's own browser after TLS decryption, so it can read tokens regardless of transport encryption; HttpOnly cookies and output encoding limit it.
  3. CPredictable TCP sequence numbers matter for blind network-level hijacking, which modern stacks randomize and which TLS integrity checks would defeat anyway.
  4. DForward secrecy protects past recordings if a server key later leaks; its absence does not expose live tokens to an attacker today.
T-05

A cybersecurity analyst has implemented encrypted communication channels, randomized TCP sequence numbers, multiple layers of firewall protection, and strengthened authentication mechanisms. These countermeasures are likely to prevent which of the following attacks?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AARP cache poisoning is prevented mainly with dynamic ARP inspection, static entries and port security, not with randomized TCP sequence numbers.
  2. BCorrect: Randomized sequence numbers, encryption and strong authentication are the classic countermeasures to TCP session hijacking, which depends on predicting or injecting into a live connection.
  3. CSQL injection is an application flaw stopped by parameterized queries and input validation; firewalls and sequence numbers do not address it.
  4. DDNS spoofing is countered with DNSSEC, source-port randomization and hardened resolvers rather than TCP sequence randomization.
T-06

A security team detects a compromised active session token originating from a corporate NAT environment. Which response action is MOST effective while minimizing false positives for legitimate users?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AMany legitimate employees share that one NAT address, so an IP block would cut them all off and generate exactly the false positives the team wants to avoid.
  2. BUser-agent strings are trivially changed and shared by many users, so a WAF rule on them is both unreliable and prone to collateral blocking.
  3. CCorrect: Invalidating the stolen token server-side ends only the compromised session, leaving other users behind the same NAT unaffected.
  4. DA global password reset disrupts everyone and may not even terminate the hijacked session if existing tokens stay valid after the reset.
T-07

In the context of securing web applications, which of the following tools can be used to hijack an authenticated session?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: Burp Suite is an intercepting web proxy used in authorized assessments to inspect and test session tokens and cookie handling in web applications.
  2. BAircrack-ng is a wireless-security suite aimed at Wi-Fi keys; it is not a web session tool.
  3. CJohn the Ripper is an offline password-cracking tool that tests password hash strength, not a tool for handling live web sessions.
  4. DWireshark captures and analyzes packets and can show cleartext cookies, but it is a passive analyzer rather than a tool for manipulating web sessions.
T-08

A development team wants to secure an SPA by abstracting tokens away from the client. Which architectural pattern securely handles tokens while issuing only HTTP cookies to the browser?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADouble-submit cookies are a CSRF defense that compares a cookie value with a request parameter; they do not keep access tokens away from the browser.
  2. BEncrypting tokens in local storage still leaves both the data and the decryption logic reachable by any script running in the page.
  3. CCORS defines which origins may read responses; a proxy built around it does not by itself take token custody away from the client.
  4. DCorrect: In a backend-for-frontend design, a server-side component obtains and stores the tokens and gives the SPA only HttpOnly, Secure session cookies.
T-09

A SIEM system flags an anomaly where an identical active session token is being used concurrently from IP addresses located in different countries. Which attack is occurring?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACredential stuffing shows up as many failed logins with leaked username-password pairs, not as one valid session token reused from two countries.
  2. BA DDoS flood produces high traffic volume from many sources, not a single valid session token in concurrent use.
  3. CCorrect: The same live token used simultaneously from distant locations is the impossible-travel signature of a stolen token being replayed; binding and revocation are the response.
  4. DLAN address spoofing works within one local segment and would not create concurrent sessions from IP addresses in different countries.
T-10

A web application implements anti-CSRF measures, yet attackers still successfully forge requests. A security review reveals the synchronizer tokens remain identical across multiple user sessions. What is the fundamental vulnerability?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AStrict Origin and Referer validation strengthens CSRF defense; it would block forged requests rather than let them through.
  2. BCorrect: Synchronizer tokens only work if they are unpredictable and unique per session or request, so a token reused across sessions can be harvested once and replayed.
  3. CSameSite=Lax reduces cross-site cookie sending and is a supplementary control; it does not explain why the synchronizer tokens themselves are identical.
  4. DHttpOnly stops scripts from reading cookies, which helps against XSS theft, but it plays no part in validating anti-CSRF tokens.
T-11

Which of the following protocols can BEST protect an organization from session hijacking attacks during employees' remote desktop sessions?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: Running RDP over TLS (often with Network Level Authentication) encrypts and authenticates the remote session, making interception and takeover far harder.
  2. BTelnet sends everything, including credentials, in cleartext, which makes sessions easy to sniff and hijack; SSH replaced it.
  3. CPPTP relies on MS-CHAPv2 and MPPE, which are cryptographically broken, so it is considered insecure for remote access.
  4. DFTP transmits credentials and data in cleartext and is a file-transfer protocol, not a way to protect remote desktop sessions.
T-12

A tester captures several session cookies from an application and observes the values MTAwMQ==, MTAwMg==, and MTAwMw==. Decoding these reveals sequential numbers. What does this predictable session ID entropy indicate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATransport encryption is a separate issue; even over TLS, sequential identifiers can be guessed without ever intercepting traffic.
  2. BCorrect: Base64 encoding hides nothing, and consecutive counter values give near-zero entropy, so other users' session IDs can be guessed; use a CSPRNG with at least 64 bits of entropy.
  3. CSession fixation means planting an ID before login; nothing here shows a pre-set identifier, only a predictable generation scheme.
  4. DCross-site scripting is script injection into pages; predictable token values point to weak ID generation, not an output-encoding flaw.
T-13

Which tool would you use to capture and analyze the data packets for detecting session hijacking in a network?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: Wireshark captures and decodes packets, letting analysts spot signs of hijacking such as duplicate sessions, ACK storms or unexpected resets.
  2. BNikto scans web servers for known vulnerable files and misconfigurations; it does not capture or analyze live traffic.
  3. CMetasploit is an exploitation framework used to validate vulnerabilities, not a packet-capture tool for monitoring sessions.
  4. DNessus is a vulnerability scanner that assesses hosts for known flaws rather than recording and inspecting network packets.
T-14

Which of the following methods is NOT typically used for session hijacking in a network environment?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASession sniffing captures traffic to obtain a valid session token and is a core hijacking method; encryption with TLS is its main countermeasure.
  2. BSession fixation plants a known session ID before the victim logs in, so it is a recognized hijacking technique; regenerating IDs at login defeats it.
  3. CCross-site scripting can expose session cookies to an attacker's script, which is why it is commonly listed as a session-theft vector.
  4. DCorrect: Brute-forcing a login targets the password to create a new session; it does not take over an existing one, so it is a credential attack rather than hijacking.
T-15

An attacker intercepts the communication between a user's browser and a web application, capturing the session ID. What type of attack is this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASQL injection inserts malicious input into database queries; it targets the back end rather than intercepting session identifiers in transit.
  2. BA denial-of-service attack aims to make a service unavailable, while capturing a session ID is about impersonating a legitimate user.
  3. CCorrect: stealing a valid session ID lets the attacker impersonate the authenticated user; TLS everywhere, Secure and HttpOnly cookies and session rotation reduce the risk.
  4. DPhishing tricks users into revealing information through deceptive messages, whereas this scenario describes intercepting an existing session's identifier.
T-16

Which protocol is most vulnerable to session hijacking due to its lack of session state tracking?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: HTTP is stateless, so applications track sessions with cookies or tokens that can be stolen or replayed, especially when sent unencrypted.
  2. BSSH encrypts and integrity-protects its sessions with strong key exchange, making hijacking far harder than with plain HTTP.
  3. CSFTP runs inside an SSH connection and inherits its encryption and integrity protection, so it is not the weak link here.
  4. DTLS is the encryption layer that protects sessions from interception, a mitigation for hijacking rather than a vulnerable protocol.
T-17

What technique allows an attacker to capture network traffic by placing themselves in the path of communication between two hosts?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASession hijacking is often the result of being in the path, but the stem describes the positioning between two hosts, which is the MITM technique itself.
  2. BCorrect: A man-in-the-middle attacker sits between two parties, for example via ARP or DNS spoofing, to read or alter their traffic; strong authentication and encryption defeat it.
  3. CA replay attack resends previously captured traffic later; it does not require sitting in the live communication path.
  4. DBrute force tries many passwords or keys until one works, with no interception of traffic between hosts.

Session hijacking, briefly answered

Where does Module 11 sit in the blueprint, and what share does it carry?

It is one of five modules in Domain 4, Network and Perimeter Hacking. The domain carries 24% of the exam, split evenly across those five modules, per EC-Council's exam blueprint v5.0 (checked Oct 11, 2026).

Why does the v13 outline list RST and blind hijacking separately?

The v13 course outline names compromising session IDs, TCP/IP hijacking, RST hijacking, blind hijacking and detection, per EC-Council's CEH course page (checked Oct 11, 2026). RST and blind hijacking are network-level variants that differ in what the attacker can see and what they achieve: one ends a connection, the other injects into it without viewing the replies.

How does this module overlap with sniffing?

At the network level, hijacking starts from a position on the path, and gaining that position is the subject of the sniffing module. Study the two together; the hands-on side of both belongs to the separate CEH (Practical) exam and an authorized lab.

Sources