Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Whitepaper "SESSION RIDING - A Widespread Vulnerability in Today's Web Applications" Dec 22 2004 11:56AM
Sverre H. Huseby (shh thathost com)
[Elihu Smails]

| But you have already stored the IP address of the attacker who
| created the session.

It sounds like you think about "Session Fixation", as described by
Mitja Kolsek in 2002. With "Session Riding" (or "Web Trojans"), the
attacker need not visit the target web site at all.

S...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus