Session Hijacking for accessing websites by the
right of other users can be done by the following
process.
Hackers must steal the victim’s Session ID,
either by sniffing data or by stealing Cookies by the
technique XSS: Cross Site Scripting.
When hackers get
the Session ID, they will use it to substitute their own
Session ID by the help of other programs such as Web
Scarab and Acunetix - HTTP Editor.
If that Session ID
is sent via Cookies, hackers will be able to use special
Browsers to help.
For example, they will use Opera or
Firefox + Cookie Editor (Add Ons) to help adjust the
Session ID value in Cookies.