Session fixation TL;DR: Attacker plants a known session ID before login; victim authenticates into it. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References https://owasp.org/www-community/attacks/Session_fixation