A security analyst is reviewing the session management implementation of a web application. The application generates session tokens by computing the MD5 hash of the concatenation of the username and the current server timestamp rounded to the nearest hour. An attacker has obtained a valid session token for her own account and discovers that she can forge tokens for other users by simply substituting the username in the hash calculation with a known target username. Which type of attack is the web application most vulnerable to?
Trap 1: Session hijacking via cross-site scripting (XSS)
Session hijacking via XSS would require the attacker to successfully inject and execute malicious JavaScript in the victim's browser, typically using document.cookie to exfiltrate the session token. This scenario describes no injection vector or client-side script execution; instead, the weakness lies entirely in the server-side token generation algorithm (username plus low-granularity timestamp). Because the attacker can compute valid tokens offline without any interaction with the victim, the flaw is predictable token generation, not script-based theft.
Trap 2: Session replay attack
A session replay attack involves capturing a valid token and reusing it later to impersonate the same user. The vulnerability described allows the attacker to create a token for a different user, not replay a captured one.
Trap 3: Session fixation
Session fixation occurs when an attacker forces a victim to use a session token that the attacker knows. Here, the attacker is able to compute a token for the victim without any interaction, so it is prediction, not fixation.
- A
Session hijacking via cross-site scripting (XSS)
Why it fails: Session hijacking via XSS would require the attacker to successfully inject and execute malicious JavaScript in the victim's browser, typically using document.cookie to exfiltrate the session token. This scenario describes no injection vector or client-side script execution; instead, the weakness lies entirely in the server-side token generation algorithm (username plus low-granularity timestamp). Because the attacker can compute valid tokens offline without any interaction with the victim, the flaw is predictable token generation, not script-based theft.
- B
Session replay attack
Why it fails: A session replay attack involves capturing a valid token and reusing it later to impersonate the same user. The vulnerability described allows the attacker to create a token for a different user, not replay a captured one.
- C
Session prediction
The session token is generated using the username and a timestamp with low granularity, making it possible for an attacker who knows the algorithm to calculate valid tokens for any user. This is a classic session prediction vulnerability.
- D
Session fixation
Why it fails: Session fixation occurs when an attacker forces a victim to use a session token that the attacker knows. Here, the attacker is able to compute a token for the victim without any interaction, so it is prediction, not fixation.