Pentesting notes
search
Ctrlk
  • 🏠/home/kabaneridev/.pt-notes
  • πŸ†Certification Preparation
    • βœ…CPTS - Completedchevron-right
    • πŸ“˜CWEE Preparationchevron-right
      • Injection Attackschevron-right
      • Attacking Authentication Mechanismschevron-right
      • Advanced XSS and CSRF Exploitationchevron-right
      • Abusing HTTP Misconfigurationschevron-right
        • [Host Header Attacks]chevron-right
        • [Web Cache Poisoning]chevron-right
        • [Session Puzzling]chevron-right
          • Introduction
          • Weak Session IDs
          • Common Session Variables - Auth Bypass
          • Common Session Variables - Account Takeover
          • Premature Session Population
          • Prevention
          • Skills Assessment
        • Skills Assessment
      • HTTP Attackschevron-right
      • HTTPS/TLS Attackschevron-right
      • Blind SQL Injectionchevron-right
      • Whitebox Pentestingchevron-right
      • Modern Web Exploitationchevron-right
      • [Deserialization Attacks]chevron-right
    • βœ…PJPT - Completedchevron-right
  • πŸ”§Core Knowledge Areas
    • πŸ”Information Gatheringchevron-right
    • 🐧Linux Privilege Escalationchevron-right
    • πŸͺŸWindows Privilege Escalationchevron-right
    • πŸ› οΈTools & Utilitieschevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. πŸ†Certification Preparationchevron-right
  2. πŸ“˜CWEE Preparationchevron-right
  3. Abusing HTTP Misconfigurations

[Session Puzzling]

Introductionchevron-rightWeak Session IDschevron-rightCommon Session Variables - Auth Bypasschevron-rightCommon Session Variables - Account Takeoverchevron-rightPremature Session Populationchevron-rightPreventionchevron-rightSkills Assessmentchevron-right
PreviousTools & Preventionchevron-leftNextIntroductionchevron-right

Last updated 14 days ago