Session Management
Authentication proves who you are once; the session carries that proof for the rest of your visit. If the session is weak, an attacker does not need your password — they need your session. This exercise covers how sessions work, the common ways they are compromised, and the settings that protect them.
Skills covered:
Authentication
Log in or create a free account to submit keys and track your progress.
What you will learn
- Explain what a session is and how the session cookie carries identity
- Name the three main session weaknesses: theft, fixation, weak expiry
- Explain why regenerating the session id at login matters
- Explain the cookie flags HttpOnly, Secure and SameSite
Before you start
These exercises cover what this one builds on.
- How HTTP Works Easy
In this exercise
- What a session is
- Three ways sessions go wrong
- Getting the lifecycle right
- The cookie flags that protect the id
🔒
This is a Pro exercise
Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.
See Pro plans Create a free account4 sections · 2 keys · 50 points