Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Whitepaper "SESSION RIDING - A Widespread Vulnerability in Today's Web Applications" Dec 20 2004 05:17PM
Elihu Smails (elihusmails2000 yahoo com)
I agree with the comments that there is a problem on
the development end that session management is
lacking. I am a developer, I can say this.:)
Sessions should track the remote IP address of the
client at a minimum, so that this problem could go
away. Many programs that I have written have custo...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus