Session Fixation Vulnerability in Web-based Applications Anthony Pell 1 min read Nov 23, 2004 Web servers are employing techniques for protecting session IDs from three classes of attacks: interception, prediction, and brute force attacks. This paper reveals a fourth class of session attacks against session IDs: session fixation attacks. Session Fixation Vulnerability in Web-based Applications Prev: Incident Response Tools For Unix, Part One: System Tools Next: Controlling Access To Your Services With xinetd