Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
BugTraq
Back to list
|
Post reply
Security Paper: Session Fixation Vulnerability in Web-based Applications
Dec 18 2002 02:01PM
Mitja Kolsek (ACROS Lists) (lists acros si)
ACROS Security is pleased to announce the publication of a security paper
about a new class of attacks on web-based applications that we named
"session fixation" attacks. The paper is available at
[ http://www.acros.si/papers/session_fixation.pdf ]
and could be useful to all web applications developers and security
analysts. We will appreciate any feedback you might provide.
Mitja Kolsek
ACROS, d.o.o.
Stantetova 4, SI - 2000 Maribor, Slovenia
web: http://www.acros.si
e-mail: mitja.kolsek (at) acros (dot) si [email concealed]
[ reply ]
Privacy Statement
Copyright 2008, SecurityFocus
ACROS Security is pleased to announce the publication of a security paper
about a new class of attacks on web-based applications that we named
"session fixation" attacks. The paper is available at
[ http://www.acros.si/papers/session_fixation.pdf ]
and could be useful to all web applications developers and security
analysts. We will appreciate any feedback you might provide.
Mitja Kolsek
ACROS, d.o.o.
Stantetova 4, SI - 2000 Maribor, Slovenia
web: http://www.acros.si
e-mail: mitja.kolsek (at) acros (dot) si [email concealed]
[ reply ]