EMZETT.
Login

Hijacking

In short: Hijacking means that attackers take over a connection, session or account.

In more detail: Depending on the target there are different forms.

In Depth

Forms

  • Session hijacking: takeover of a logged-in session, for example via stolen cookies.
  • DNS hijacking: requests are redirected to wrong IP addresses.
  • BGP hijacking: routes on the internet are announced wrongly.
  • Clickjacking: invisible elements intercept clicks.
  • Account takeover: takeover of an account with stolen credentials.

Protection

HTTPS and HSTS, secure cookies (Secure, HttpOnly, SameSite), MFA, DNSSEC, short session duration.

See also: Cookies, Infostealer Trojan, MFA