Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: Whitepaper "SESSION RIDING - A Widespread Vulnerability in Today's Web Applications" Dec 20 2004 05:56PM
Mark Burnett (mb xato net)
Yvan G.J. Boily wrote:
> This name for the issue is misleading; this is a state management
> issue combined with a session management issue.
>
> Although there is an attempt to separate this type of an attack,
> it is still a session hijacking attack

I actually like Thomas' name for this and I thin...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus