What is session hijacking?¶
Session hijacking is unauthorised use of an existing authenticated session.
Instead of defeating the login process again, the attacker uses session material that the service already trusts.
Identify the actual session¶
Do not start with geography alone.
Look for:
- session ID;
- token family;
- browser/application;
- device fields;
- source infrastructure;
- user agent;
- activity tied to that session;
- session creation and revocation.
A useful example might look like:
That gives you a defined session to investigate.
Test legitimate explanations¶
The same account may appear from different places because of:
- VPN;
- mobile networks;
- corporate proxy;
- authorised second device;
- remote desktop;
- shared access.
So correlate the session with device and account activity rather than calling every location change hijacking.
Look for unauthorised continuation¶
Useful evidence may include:
- browser/session theft artefacts;
- malware;
- token use without reauthentication;
- unfamiliar account actions inside the same session;
- device mismatch;
- provider security alerts.
The practical point is: prove unauthorised use of a defined session through its identifiers and activity. Geography and missing login records are supporting features, not the whole proof.