3 4 5 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

What is Hijacking

Representation of a hijacking attackDefinition:

Hijacking is the unauthorized takeover, alteration, or redirection of a digital resource or its control mechanism. The term applies to domains, network settings, browsers, authenticated sessions, traffic routes, and content.

It does not describe a single technique. Each form compromises a different element and requires specific controls. A browser change, the theft of a session cookie, and the fraudulent transfer of a domain can all produce redirection or impersonation, but they do not necessarily have the same cause.

Scope of the concept

The common feature is a loss of control by the legitimate user, owner, or administrator. An attacker may gain access to an account, change a setting, appropriate an identifier, or interfere with a communication.

Hijacking can affect the client side, such as when a malicious extension changes the search provider in a browser, or infrastructure, such as when DNS records are altered. It can also occur inside an application when a third party uses a valid token to assume a session.

The word is also used in content and brand contexts to describe the improper appropriation of visibility, identity, or editorial material. That usage is separate from technical forms involving effective control of an account, session, or infrastructure.

Forms of hijacking

Classification depends on the compromised resource and the point at which interference occurs. Common forms include:

  • Domain hijacking: a third party gains access to the registrar or administrative account and transfers or modifies the domain without authorization.
  • DNS hijacking: records or responses are changed to direct requests toward infrastructure controlled by an attacker.
  • Browser hijacking: an extension, program, or setting alters the homepage, search provider, new tabs, or browsing destination.
  • Session hijacking: a valid identifier is obtained or fixed so that someone can act with the permissions of an authenticated user.
  • Traffic hijacking: redirects, links, or routes are manipulated to divert visits to a different destination.
  • Content hijacking: third-party material is copied or republished as original work, or its attribution is displaced.

URL hijacking can refer to different situations, from a malicious redirect to older practices involving temporary responses. Diagnosis requires identifying the specific mechanism rather than inferring it solely from a change in search results.

Signs of compromise

Indicators vary by form of hijacking. A single anomaly does not confirm an attack, but several unauthorized changes justify a review of accounts, devices, and records:

  • Browser changes: search provider, homepage, proxy, or extensions that reappear after settings are restored.
  • Unexpected redirects: links or visits that end on different domains without a known legitimate rule.
  • Account activity: logins, password changes, sessions, or devices that the owner does not recognize.
  • DNS alterations: records, authoritative servers, or registrar contacts modified without approval.
  • Anomalous sessions: actions performed through a valid account from locations or clients inconsistent with normal usage.
  • Replicated content: extensive copies that remove authorship, change links, or appear before systems recognize the original source.

Pop-ups, poor performance, or an unusual search result may also result from legitimate settings, errors, or different forms of malware. Confirmation requires related evidence such as change history, access logs, and DNS resolution.

Operational impact

The damage depends on the permissions obtained and the duration of exposure. Hijacking can affect several areas:

  • Security: theft of credentials, data, tokens, or information entered on a fraudulent page.
  • Continuity: service disruption, loss of email, account lockout, or website unavailability.
  • Reputation: impersonation, fraudulent messages, or distribution of content under a legitimate identity.
  • Organic visibility: redirects, content changes, crawl errors, or conflicting signals for search engines.

Copied content does not automatically trigger a penalty against the original site. It may create attribution, discovery, or canonical-selection problems, so it should be investigated as possible duplicate content, not treated as sufficient proof of technical hijacking.

Risk management

Protection must be applied at the relevant control point. Antivirus software may help with malicious programs, but it cannot repair a compromised registrar account or unsafe session management. The main measures include:

  • Protect accounts: use unique credentials, multifactor authentication, and alerts for sensitive changes.
  • Lock domains: enable transfer locks and restrict changes to registrar and DNS settings.
  • Encrypt communications: use HTTPS with current TLS and keep session identifiers out of URLs.
  • Secure sessions: rotate identifiers after authentication, limit their lifetime, and protect cookies with appropriate attributes.
  • Reduce injection: validate input, encode output, and apply policies that limit unauthorized script execution.
  • Control software: review extensions, keep systems updated, and remove unrecognized programs.
  • Monitor changes: track DNS, redirects, logins, files, and settings across digital properties.

During an incident, initial containment includes revoking exposed sessions and credentials, isolating the affected device or account, and restoring settings from a trusted source. Records should then be preserved, the scope determined, and the domain, DNS, browser, and public pages checked for a return to their legitimate state.