How unit 2 is examined
This unit covers web-based attacks and cyber-criminal behaviour; session hijacking carries the most marks, then online frauds, piracy, intrusions, password sniffing, cyber terrorism and web server hacking.
Web jacking
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Web jacking is the forceful takeover of a website, in which the attacker tricks the owner or redirects visitors to a fake look-alike page and then controls its content.</mark>
Key points.
- The attacker clones the target site and hosts it on a similar domain name.
- The victim is lured by a phishing link, and a link such as "click here for the new page" leads to the fake site.
- Once the owner or the visitor is fooled, the attacker changes the content, steals data or demands ransom for the return of control.
- Example: in the 2001 Gold Fish case the attacker hijacked a site and demanded a ransom for its return.
Asked: [7 marks] (Dec 2025) Explain Web jacking, online fraud and software piracy with examples.
Online Frauds
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. <mark>A fraud in cyber crime is deception carried out through computers or the Internet to gain money, property or information unfairly.</mark>
Key points.
- Credit card fraud is the use of stolen card numbers or cloned cards to make purchases or withdrawals without the owner's consent.
- Phishing is sending fake emails or sites that imitate a trusted body to trick users into revealing passwords or card details.
- Auction fraud means a seller takes payment for goods that are never delivered, or the item is misrepresented or fake.
- Lottery fraud is a message claiming that the victim has won a prize, which is released only after a "processing fee" is paid.
- Investment fraud promises very high returns, such as Ponzi or fake trading schemes, and disappears with the deposits.
- Identity theft fraud uses another person's personal data to open accounts or take loans.
- Impact: victims lose money and trust, and banks and e-commerce sites suffer losses and reputational damage.
Answer frame. Open with the definition of fraud as deception for gain; then define each type (points 1-6) in one or two sentences with an example; close with the losses caused and the prevention (awareness, two-factor authentication, reporting to cyber cell).
Asked: [7 marks] (Jun 2020, Jun 2025) Explain the term 'Frauds' with reference to cyber crime and define the various types of online frauds.
Software Piracy
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. <mark>Software piracy is the unauthorised copying, use or distribution of copyrighted software in violation of its licence.</mark>
Key points.
- Softlifting means buying one licensed copy and installing it on many computers, which the licence does not allow.
- Counterfeiting is producing and selling fake copies of software that look like the genuine product.
- Hard-disk loading is a dealer installing unlicensed software on the computers he sells.
- Internet or online piracy is uploading or downloading cracked software through torrents and file-sharing sites.
- Cracking and key generation remove the licence protection, and licence overuse lets more users than the licence permits.
- Effects: the industry loses revenue, jobs and investment, the government loses tax, and users risk malware in cracked copies.
- Legal prevention: the Copyright Act 1957 (Section 63 and 63B) and the IT Act 2000 punish piracy with imprisonment and fine; software firms use activation keys and licence audits.
Answer frame. Open with the definition; list the forms (points 1-5) with one line each; then effects; close with the legal and technical prevention.
Asked: [7 marks] (Nov 2019, Jun 2020) What do you mean by software piracy? Explain "Software piracy". Write down various activities that constitute software piracy.
Computer Network Intrusions
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. <mark>A network intrusion is any unauthorised access to or activity on a network; an Intrusion Detection System (IDS) is a tool that monitors traffic or hosts and raises an alert when it sees such activity.</mark>
Key points.
- A Host-based IDS (HIDS) runs on a single machine and watches its logs, files and system calls.
- A Network-based IDS (NIDS) sits on the network and inspects the packets passing through it.
- Signature-based detection matches traffic against a database of known attack patterns, so it is accurate on known attacks but misses new ones.
- Anomaly-based detection compares behaviour with a normal profile, so it can find new attacks but gives more false alarms.
- Components are the sensors or agents that collect data, the analysis engine, the signature or profile database, and the alert and console module.
- Placement: a NIDS is placed behind the firewall or on a mirror (SPAN) port of the switch to see the traffic.
- A firewall only blocks traffic by rules, an IDS only detects and alerts, and an IPS detects and also blocks the attack.
Common network attacks (Nov 2023).
| Attack | Working and damage |
|---|---|
| DoS/DDoS | Floods the target with requests so that the service becomes unavailable. |
| Man-in-the-middle | Sits between two parties and reads or alters the traffic. |
| Phishing | Fake messages steal credentials. |
| Malware | Viruses, worms and ransomware damage or lock data. |
| SQL injection | Malicious queries read or modify the database. |
| Sniffing and spoofing | Capture packets or fake addresses to gain access. |
<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u2-01" viewBox="0 0 338 252" width="338" height="252" role="img" aria-label="NIDS placed behind the firewall on a mirror port (Net = Internet, FW = firewall, IDS = intrusion detection sensor, LAN = internal network)"><style>#dsfig-u2-01 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u2-01 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u2-01 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u2-01 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u2-01 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u2-01 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u2-01 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u2-01 .t{fill:#16181D;font-weight:500}#dsfig-u2-01 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u2-01 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u2-01 .dot{fill:#16181D}#dsfig-u2-01 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u2-01 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u2-01 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u2-01 .ah{fill:#454C5A}#dsfig-u2-01 .ah.hi{fill:#2340B8}#dsfig-u2-01 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u2-01 .wl .t{font-size:12px;font-weight:700}#dsfig-u2-01 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u2-01 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u2-01 .e{stroke:#B1B7C3}html.dark #dsfig-u2-01 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u2-01 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u2-01 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u2-01 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u2-01 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u2-01 .t{fill:#E6E8ED}html.dark #dsfig-u2-01 .t.inv{fill:#0F1115}html.dark #dsfig-u2-01 .kd{stroke:#E6E8ED}html.dark #dsfig-u2-01 .dot{fill:#E6E8ED}html.dark #dsfig-u2-01 .ann{fill:#8FA3FF}html.dark #dsfig-u2-01 .lbl{fill:#858D9C}html.dark #dsfig-u2-01 .ptr{fill:#8FA3FF}html.dark #dsfig-u2-01 .ah{fill:#B1B7C3}html.dark #dsfig-u2-01 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u2-01 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u2-01 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u2-01 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah3" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh3" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M59,126 L148,126" marker-end="url(#ah3)"/><path class="e" d="M184.8,136.5 L280.5,200.4" marker-end="url(#ah3)"/><path class="e" d="M184.8,115.5 L282.2,50.5"/><g class="wl"><rect x="206.4" y="74" width="54.3" height="18" rx="9"/><text class="t" x="233.5" y="83" dy=".35em" text-anchor="middle">mirror</text></g><circle class="n" cx="40" cy="126" r="18"/><text class="t" x="40" y="126" dy=".35em" text-anchor="middle">Net</text><circle class="n" cx="169" cy="126" r="18"/><text class="t" x="169" y="126" dy=".35em" text-anchor="middle">FW</text><circle class="n" cx="298" cy="40" r="18"/><text class="t" x="298" y="40" dy=".35em" text-anchor="middle">IDS</text><circle class="n" cx="298" cy="212" r="18"/><text class="t" x="298" y="212" dy=".35em" text-anchor="middle">LAN</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">NIDS placed behind the firewall on a mirror port (Net = Internet, FW = firewall, IDS = intrusion detection sensor, LAN = internal network)</figcaption></figure>
Answer frame. Open with the definition of intrusion and IDS; draw the placement figure; develop types (1-4), components (5), then the comparison with firewall and IPS (7); close with the limitation that an IDS alone cannot stop attacks. For the attacks question, define a network attack and give the table.
Asked: [7 marks] (Nov 2019) Discuss the concept of Intrusion detection system. Asked: [7 marks] (Nov 2023) What are the common cyber-attacks which can be used by Hackers to damage network? Asked: [7 marks] (Dec 2025) Discuss Computer network intrusions, password sniffing and identity theft.
Password Sniffing
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. <mark>Password sniffing is capturing passwords and other credentials as they travel across a network, using a packet sniffer.</mark>
Key points.
- A packet sniffer such as Wireshark or tcpdump puts the network card in promiscuous mode so that it reads every packet on the segment.
- Protocols that send data in plain text, such as HTTP, FTP, Telnet and POP3, expose the passwords directly.
- Sniffing is easy on shared media, public Wi-Fi and hubs, and stronger with ARP spoofing or a man-in-the-middle position.
- The stolen password is then used to log in, or is passed to the cracking stage.
- Prevention: use encrypted protocols (HTTPS, SSH, VPN), switched networks, strong passwords and multi-factor authentication.
Answer frame. Open with the definition; then tools and working (1-4); close with prevention (5) and the impact, which is account takeover. For "Password Sniffing and Session Hijacking", write this topic and then the session hijacking definition and methods; for "and cyber terrorism", add that topic's definition, examples and impact.
Asked: [7 marks] (Dec 2024) Explain the terms Password Sniffing and Session Hijacking. Asked: [7 marks] (Jun 2025) What is password sniffing and cyber terrorism?
Identity Theft
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Identity theft is the fraudulent use of another person's personal identifying information, such as name, PAN, Aadhaar or card number, for gain.</mark>
Key points.
- Types: financial (loans and card misuse), criminal (giving the victim's name to police), medical (treatment or insurance claims) and synthetic (mixing real and fake data into a new identity).
- Techniques: phishing emails and fake sites, skimming card data with a reader, malware and keyloggers, and data breaches.
- Other techniques are shoulder surfing, dumpster diving and social engineering.
- Consequences are financial loss, a damaged credit record and legal trouble for the victim.
Asked: [7 marks] (Jun 2025) What do you mean by identity theft? Describe its types? What techniques are used for ID theft?
Cyber terrorism
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. <mark>Cyber terrorism is the use of computers and the Internet to attack critical systems and create fear, disruption or harm in order to further a political, religious or ideological aim.</mark>
Key points.
- Motives are political, religious or ideological, aimed at pressuring a government or the public.
- Targets are critical infrastructure such as power grids, banking, air traffic, defence and government websites.
- Methods include DDoS, malware, hacking, defacement and spreading propaganda or recruiting online.
- Difference from cyber crime: cyber crime seeks personal or financial gain, while cyber terrorism seeks to cause fear and damage for a cause.
- Power and characteristics: it is cheap, anonymous, works across borders, needs no physical presence and can hit many victims at once.
- Challenges of cybercrime: jurisdiction across countries, anonymity of the criminal, huge scale, weak evidence and rapidly changing technology.
- Impact: loss of essential services, economic loss and a threat to national security; the 2007 attacks on Estonia are an example.
Answer frame. Open with the definition; give motives, targets and methods (1-3); the distinction from cyber crime (4); then power and challenges (5-6) if asked; close with impact and example (7).
Asked: [7 marks] (Dec 2020) Define the term cyber terrorism in detail. Asked: [7 marks] (Nov 2022) Talk about the different issues and challenges of cybercrime. Also explain the power and characteristics of cyber terrorism. Asked: [7 marks] (Dec 2025) Explain Cyber terrorism and virtual crimes. Discuss the perception of cyber criminals such as hackers and extremist groups.
Virtual Crime
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Virtual crime is crime committed in or against virtual worlds and online communities, such as online games and social platforms.</mark>
Key points.
- Examples are theft of virtual property or currency, fraud in online games, cyber stalking and harassment of avatars.
- The harm is real even though the setting is virtual, because virtual goods can be bought and sold for real money.
- Law is unclear, because it is hard to decide whether virtual property is protected and which country's court applies.
Perception of cyber criminals
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Hacking is gaining unauthorised access to a computer system or network; a hacker is the person who does it, and hackers, insurgents and extremist groups are seen as the main cyber criminals.</mark>
Key points.
- White hat hackers are ethical hackers who test systems with permission to find and fix weaknesses.
- Black hat hackers (crackers) break in illegally for money, revenge or damage.
- Grey hat hackers break in without permission but without malicious intent, and often report the flaw afterwards.
- Others are script kiddies (use ready-made tools), hacktivists (political protest) and insurgents or extremist groups who use the Internet for propaganda, funding and attacks.
Asked: [7 marks] (Jun 2020) Explain the term "Hacking". What are the various classifications of hackers? Mention them.
Web server hacking
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. <mark>An attack on a web server is an attempt to exploit its software, configuration or applications in order to deface the site, steal data, disrupt service or gain control.</mark>
Key points.
- Objectives are defacement, data theft, denial of service, planting malware and using the server as a launch pad.
- Common vulnerabilities are misconfiguration and default accounts, unpatched software, SQL injection, cross-site scripting (XSS), and weak passwords.
- Phases are footprinting, scanning and enumeration, exploiting a flaw, gaining access, and then covering tracks.
- Avoid it by patching the server and applications regularly.
- Harden the server by removing default accounts, unused services and sample files, and by giving least privilege.
- Use a firewall or WAF, input validation and HTTPS.
- Monitor logs with an IDS, keep regular backups and control access with strong passwords and multi-factor authentication.
Answer frame. Open with the definition and objectives; list vulnerabilities (2) with one line each; then the steps to avoid it (4-7) as a numbered list; close with the point that layered security lowers the risk. For a short note, add the phases (3).
Asked: [7 marks] (Jun 2020, Dec 2024) What do you understand by "Attack on web server"? Explain the steps taken to avoid web server hacking. Asked: [7 marks] (Dec 2025) Write short notes on web server hacking and session hijacking.
Session hijacking
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>
Definition. <mark>Session hijacking is the takeover of an active, authenticated session between a user and a server by stealing or predicting the session ID (token), so that the attacker acts as the user without knowing the password.</mark>
<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u2-02" viewBox="0 0 338 252" width="338" height="252" role="img" aria-label="U = user, S = web server, A = attacker; the attacker steals the session token and uses it on the server"><style>#dsfig-u2-02 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u2-02 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u2-02 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u2-02 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u2-02 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u2-02 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u2-02 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u2-02 .t{fill:#16181D;font-weight:500}#dsfig-u2-02 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u2-02 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u2-02 .dot{fill:#16181D}#dsfig-u2-02 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u2-02 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u2-02 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u2-02 .ah{fill:#454C5A}#dsfig-u2-02 .ah.hi{fill:#2340B8}#dsfig-u2-02 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u2-02 .wl .t{font-size:12px;font-weight:700}#dsfig-u2-02 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u2-02 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u2-02 .e{stroke:#B1B7C3}html.dark #dsfig-u2-02 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u2-02 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u2-02 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u2-02 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u2-02 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u2-02 .t{fill:#E6E8ED}html.dark #dsfig-u2-02 .t.inv{fill:#0F1115}html.dark #dsfig-u2-02 .kd{stroke:#E6E8ED}html.dark #dsfig-u2-02 .dot{fill:#E6E8ED}html.dark #dsfig-u2-02 .ann{fill:#8FA3FF}html.dark #dsfig-u2-02 .lbl{fill:#858D9C}html.dark #dsfig-u2-02 .ptr{fill:#8FA3FF}html.dark #dsfig-u2-02 .ah{fill:#B1B7C3}html.dark #dsfig-u2-02 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u2-02 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u2-02 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u2-02 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah4" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh4" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M61,40 L277,40" marker-end="url(#ah4)" marker-start="url(#ah4)"/><path class="e hi" d="M157.6,196.8 L52.6,56.8" marker-end="url(#ahh4)"/><path class="e" d="M180.4,196.8 L285.4,56.8" marker-end="url(#ah4)"/><g class="wl"><rect x="138.3" y="31" width="61.5" height="18" rx="9"/><text class="t" x="169" y="40" dy=".35em" text-anchor="middle">session</text></g><g class="wl hi"><rect x="81" y="117" width="47.1" height="18" rx="9"/><text class="t" x="104.5" y="126" dy=".35em" text-anchor="middle">sniff</text></g><g class="wl"><rect x="210" y="117" width="47.1" height="18" rx="9"/><text class="t" x="233.5" y="126" dy=".35em" text-anchor="middle">token</text></g><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">U</text><circle class="n" cx="298" cy="40" r="18"/><text class="t" x="298" y="40" dy=".35em" text-anchor="middle">S</text><circle class="n" cx="169" cy="212" r="18"/><text class="t" x="169" y="212" dy=".35em" text-anchor="middle">A</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">U = user, S = web server, A = attacker; the attacker steals the session token and uses it on the server</figcaption></figure>
Key points.
- A session is the period after login in which the server recognises the user by a session ID stored in a cookie or URL.
- Passive hijacking only watches and captures the traffic, while active hijacking takes over the session and may knock the user out.
- Network-level hijacking attacks TCP sessions (sequence number prediction), while application-level hijacking attacks the web session token.
- Methods are packet sniffing on unencrypted traffic, cross-site scripting (XSS) to steal the cookie, session fixation (the attacker sets a known ID before login), sidejacking (sniffing the cookie on open Wi-Fi) and predicting weak session IDs.
- Initiation steps are to find an active session, capture or guess the token, and then replay it to the server to take over.
- Problems caused are data theft, impersonation, financial fraud and loss of privacy.
- Cookies raise the threat because they carry the session ID, so theft, tampering or CSRF and XSS use of a cookie gives access; the flags HttpOnly (hides it from scripts), Secure (only HTTPS) and SameSite (blocks cross-site sending) reduce this.
- Prevention: use HTTPS everywhere, secure cookies, regenerate the session ID after login, set short timeouts and logout, use multi-factor authentication, an IDS and user awareness.
| Basis | Spoofing | Session hijacking |
|---|---|---|
| Meaning | Faking an identity such as an IP, email or MAC address. | Taking over an already established session. |
| Types | IP, email, DNS, ARP spoofing. | Active and passive, network and application level. |
| Timing | Before or without a session. | After the user has logged in. |
| Needs | A forged address or identity. | A valid session token. |
| Goal | Pretend to be a trusted party. | Act as the logged-in user. |
| Example | Fake sender email. | Stolen cookie on public Wi-Fi. |
Answer frame. Open with the definition; draw the figure; develop points 1-5 in order, then problems (6); close with prevention (8). For prevention, lead with causes (4), then 8. For cookies, define cookies then point 7. For the comparison, define both with types and give the table with one line on implications.
Asked: [7 marks] (Nov 2019) What do you mean by session hijacking? Asked: [7 marks] (Jun 2020, Jun 2025) Explain "Session Hijacking" in detail along with the methods for initiating session hijacking. What problems may be generated due to session hijacking? Asked: [7 marks] (Nov 2022, Nov 2023) Determine the conceptual differences between Spoofing and Session Hijacking. Asked: [7 marks] (Nov 2022) Explain the role of cookies in enhancing threats against various web applications? Asked: [7 marks] (Nov 2023) Explain how to prevent session hijacking attacks from happening? Asked: [7 marks] (Dec 2025) Write short notes on web server hacking and session hijacking.
Last-minute revision
- Web jacking is forceful takeover of a website through a fake look-alike page.
- Fraud is deception through the Internet for unfair gain.
- Piracy forms are softlifting, counterfeiting, hard-disk loading and online piracy; Copyright Act Section 63.
- IDS detects, IPS detects and blocks, and a firewall filters by rules.
- IDS types are host or network, and signature or anomaly.
- Password sniffing needs a packet sniffer and a network card in promiscuous mode.
- Identity theft types are financial, criminal, medical and synthetic.
- Cyber terrorism seeks fear for a cause; cyber crime seeks gain.
- Hackers are white hat (ethical), black hat (criminal) and grey hat (in between).
- Session hijacking methods are sniffing, XSS, fixation, sidejacking and prediction.
- Cookie flags are HttpOnly, Secure and SameSite.
Memory hooks
- Session hijacking methods: "SFXS", meaning Sniff, Fixation, XSS, Sidejack.
- Piracy: "Soft, Fake, Hard, Net" for softlifting, counterfeiting, hard-disk loading and online.
- IDS "detects", IPS "prevents", and the firewall "filters".
- Hat colours: white is good, black is bad, grey is in between.
- Cookie flags: "HSS" for HttpOnly, Secure, SameSite.
Coverage checklist
- Web jacking: definition, examples (Dec 2025 combined question).
- Online Frauds: fraud types (Jun 2020, Jun 2025).
- Software Piracy: forms, effects, law (Nov 2019, Jun 2020).
- Computer Network Intrusions: IDS and network attacks (Nov 2019, Nov 2023, Dec 2025).
- Password Sniffing: tools and prevention (Dec 2024, Jun 2025, Dec 2025).
- Identity Theft: types and techniques (Jun 2025, Dec 2025).
- cyber terrorism: definition, power, challenges (Dec 2020, Nov 2022, Jun 2025, Dec 2025).
- Virtual Crime: definition and examples (Dec 2025).
- Perception of cyber criminals: hackers, insurgents and extremist group etc.: hacker classes (Jun 2020, Dec 2025).
- Web servers were hacking: attack and prevention (Jun 2020, Dec 2024, Dec 2025).
- session hijacking: definition, methods, comparison, cookies, prevention (Nov 2019, Jun 2020, Nov 2022, Nov 2023, Jun 2025, Dec 2024, Dec 2025).