Skip to content

What it blocks

Session attacks

Someone tries to force a visitor onto a session they control.

What it is

A request that tries to set a visitor's session id from outside the site.

  • A session id passed in a link from another website

Why it matters

If a visitor signs in on a session the attacker chose, the attacker is signed in as them.

If a real visitor is ever stopped

Some older sites pass the session in the address on purpose. Mark the request as real if yours does.