Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Whitepaper "SESSION RIDING - A Widespread Vulnerability in Today's Web Applications" Dec 22 2004 05:47PM
Florian Weimer (fw deneb enyo de)
* Eran Tromer:

> In Section 6.1 ("Countermeasures" / "Use secrets"), you seem to
> concentrate on secrets that are explicitly stored in the server-side
> session record. But one can also use a secret that is computed on-the-fly:
>
> secret = SHA1(site_secret, session_id)
>
> or, in the absence of...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus