Security

Session Fixation Tester

A session fixation tester checks the one behaviour that stops fixation attacks: whether the session identifier changes when a user logs in. Paste the ID before and after authentication and the Set-Cookie header, and it reports rotation, entropy and the cookie flags, all computed from what you provide.

Last reviewed by the Radiatus Cloud team

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

The attack it tests for

In session fixation, an attacker plants a session ID they know (through a link, a subdomain cookie or a header injection), waits for the victim to log in with it, and then uses the same ID to ride the now-authenticated session. The defence is simple and absolute: regenerate the session ID at every privilege change, above all at login. If the ID before and after login are identical, the application is vulnerable.

What you paste and what it computes

The before and after IDs are compared directly; a match is reported as critical. The after-ID is measured for length and Shannon entropy, since OWASP recommends at least 64 bits, roughly 16 hex characters from a cryptographic generator, and a purely numeric ID is flagged as likely sequential and guessable.

The cookie audit

Paste the login response's Set-Cookie line and the tester checks each flag:

  • Secure missing: the cookie travels over plain HTTP if any http link is followed.
  • HttpOnly missing: any cross-site scripting flaw can read it via document.cookie.
  • SameSite not Lax or Strict: cross-site requests carry the session, enabling CSRF.
  • Domain set: every subdomain can read and set the cookie, the classic fixation channel from a compromised subdomain.
  • A __Host- prefix is called out as the strongest shape, since it forces Secure, Path=/ and no Domain.

How to capture the values

Open browser DevTools, watch the Application or Storage panel for the session cookie, note it before submitting the login form and again after, and copy the Set-Cookie header from the Network tab's login response.

Related tools

  • Cookie Security Analyzer — A new tool extracted from the codebase.
  • CSRF Risk Checker — Analyze forms and APIs for CSRF vulnerabilities and get remediation guidance.
  • JWT Risk Analyzer — Paste a JWT to decode its header and payload and flag security risks: alg none, jku/x5u header injection, missing expiry, millisecond timestamps and personal data in claims.
  • Password Entropy Visualizer — Measure password entropy in bits and see what that actually means for how long a password survives an attack.

Frequently Asked Questions

How do I get the before and after session IDs?

Open DevTools, go to Application or Storage, find the session cookie (often PHPSESSID, JSESSIONID, connect.sid or similar), note its value before you submit the login form, then note it again after login completes.

What does it mean if the ID does not change?

The application is vulnerable to session fixation. Fix it by regenerating the session at login: session_regenerate_id(true) in PHP, request.session.cycle_key() in Django, req.session.regenerate() in Express, or the equivalent in your framework.

Is this an active exploit tool?

No. It analyses values you capture yourself from an application you are authorised to test. It sends nothing and attacks nothing; the verdict is computed from the IDs and header you paste.

Why does the Domain attribute matter for fixation?

A cookie scoped to a parent domain can be set by any subdomain. If one subdomain is compromised or user-controlled, it can plant a session ID that the main site then adopts, which is a fixation vector.

What entropy should a session ID have?

OWASP recommends at least 64 bits of entropy from a cryptographically secure generator, which is about 16 hexadecimal or 11 base64 characters. Shorter or predictable IDs can be brute-forced or guessed.

Privacy & Security

Testing done locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.