Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Whitepaper "SESSION RIDING - A Widespread Vulnerability in Today's Web Applications" Dec 21 2004 06:47PM
Elihu Smails (elihusmails2000 yahoo com)
But you have already stored the IP address of the
attacker who created the session. Therefore when the
victim connects to your web app, you do not allow them
in because the IP address does not match what is
currently stored in the session information.

--- "Sverre H. Huseby" <shh (at) thathost (dot) com [email concealed]> wro...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus