Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. Cyber Security
  3. Question
Cyber Security

Is it possible to exploit ASP NET_SessionId?

Asked by Anisha Dalal May 27, 2024 5.0K views 3 answers
Share

About this question

 I am pen-testing an ASP.NET application that is exhibiting Session Fixation behaviour. The application is using cookie based sessions. Basically:


When you land on the page no Session cookie is created

After login ASP.NET_SessionId cookie is created

On logout and repeated login the cookie value remains the same (there is no cookie value regeneration)

I have been able to perform Session Fixation attack manually:

I have landed on the page

I manually created a ASP.NET_SessionId cookie with some value (for the attacker)

I opened a new browser session and set the exact same cookie (for the victim)

I logged in as victim in this new browser session

In the attacker’s browser session I was now able to browse the web site as the victim

I am now having problems exploiting this Session Fixation vulnerability in real conditions. I need to create or modify the ASP.NET_SessionId cookie in some manner. From what I am able to tell, there is no XSS vulnerability on the web site which I could use.

I have been playing with two most notable attack variations but with no luck (a case where a victim would click on a link which would set a cookie on the web page):

JavaScript

https://www.example.com/[removed][removed]='ASP.NET_SessionId=THISISAFIXATEDCOOKIE; expires=Thu, 18 Dec 2015 12:00:00 UTC; path=/; domain=example.com; path=/'[removed]

HTML Injection

https://www.example.com/<meta http-equiv="Set-Cookie" content="ASP.NET_SessionId=THISISAFIXATEDCOOKIE; expires=Thu, 18 Dec 2015 12:00:00 UTC; path=/; domain=example.com; path=/">

Whatever I tried I’ve either hit a default error page or the landing page with no created/modified cookie. Am I missing something with these two attack vectors?

Is there any other method I could try in creating or modifying the victim’s ASP.NET _SessionId cookie besides using man-in-the-middle or man-in-the-browser (malware based) attacks?

Your answer

3 Answers

Ranjana Admin JanBask Expert Latest answer

Answered on Mar 20, 2025

Yes, the ASP.NET_SessionId can be exploited if proper security measures are not in place. The session ID is used to track a user's session in an ASP.NET application, and if compromised, an attacker could hijack a user’s session. Here are some common attack scenarios:

1. Session Hijacking

  • If an attacker steals a valid ASP.NET_SessionId, they can impersonate a user and gain unauthorized access.
  • This can happen through XSS (Cross-Site Scripting) if the session ID is exposed in JavaScript or the URL.

2. Session Fixation

  • If an application allows an attacker to set a predefined session ID for a user, the attacker can force the victim to use a known session and take control once they authenticate.
  • Mitigation: Regenerate the session ID after login.

3. Session ID in URL (Insecure)

  • If the session ID is passed in the URL (e.g., example.com?ASP.NET_SessionId=xyz), it can be logged in browser history or leaked through referrer headers.
  • Mitigation: Always store session IDs in secure cookies, not in URLs.

How to Protect Against Exploitation?

Use Secure Cookies:

  SessionStateSection sessionStateSection = (SessionStateSection)ConfigurationManager.GetSection("system.web/sessionState");sessionStateSection.CookieSameSite = SameSiteMode.Strict;

  • Enable HTTPS to encrypt session cookies.
  • Regenerate Session ID after login to prevent fixation attacks.
  • Set HttpOnly and Secure Flags on session cookies.

By implementing these security measures, you can significantly reduce the risk of ASP.NET_SessionId exploitation.

Was this helpful?

More Cyber Security discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest Cyber Security Blogs

Guides, tips and career advice on Cyber Security from JanBask experts.