Back to Blog

What Is Session Hijacking and How to Prevent It

PB

Patrick Bushe

September 12, 2024 · 5 min read

When you sign in to a website, it gives your browser a session token, usually stored in a cookie, so you stay signed in. Session hijacking is when an attacker steals that token and uses it to get into your account. They don't need your password, and often not your two-step code either.

How sessions get stolen

  • Infostealer malware. The most common route today. Malware from fake downloads, cracked software or fake updates copies cookies straight from your browser.
  • Phishing proxies. A fake login page passes everything you type to the real site and captures the session token it sends back, even after two-step verification.
  • Cross-site scripting (XSS). A flaw in a website lets an attacker run code that reads session cookies.
  • Unencrypted connections. On sites without HTTPS, someone on the same network could read the cookie. This is rare now that most sites use HTTPS.
  • Session fixation. An attacker tricks you into using a session ID they already know, on sites that don't issue a new one at login.

Warning signs

  • Security alerts about sign-ins from devices or places you don't recognize.
  • Messages, posts or purchases you didn't make.
  • Settings changed, such as a new recovery email.

How to prevent it

  1. Avoid malware. Download software only from official sources and never run "fixes" a website tells you to paste. See fake update popups.
  2. Use passkeys where you can. They only work on the real site, so phishing proxies can't use them.
  3. Check the address before signing in, and let your password manager fill logins; it won't fill on a fake site.
  4. Keep Chrome and your system updated.
  5. Turn on Enhanced protection in Settings → Privacy and security → Security.
  6. Sign out of important accounts on shared computers, and review signed-in devices regularly.

If you think a session was stolen

  1. Use the account's "sign out of all other sessions" option. For Google, go to your account's Security page → Your devices.
  2. Change your password, which on most sites also ends other sessions.
  3. Check recovery details, forwarding rules and connected apps for changes.
  4. Scan your computer for malware; otherwise the new session can be stolen too.

For website developers

  • Set session cookies as HttpOnly, Secure and SameSite.
  • Issue a new session ID at login and at privilege changes.
  • Expire sessions after inactivity, and ask users to sign in again for sensitive actions.
  • Prevent XSS with output encoding and a Content Security Policy.

Related protections

Session hijacking is different from clipboard hijacking, where malware or a site swaps what you copy. Clipboard Guard blocks sites from reading your clipboard, but it doesn't protect sessions. See also two-factor authentication.

More Tools by Patrick Bushe

Free Chrome extensions to boost your productivity and privacy