HACKR.GG
LabsSession Fixation
Session SecurityHard

Session Fixation

The app issues a session token before login and never rotates it afterwards. Fix the session ID before the victim logs in and inherit their authenticated session.

↗ View walkthrough
// Machine control
Checking session...
// Submit flag