Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Whitepaper "SESSION RIDING - A Widespread Vulnerability in Today's Web Applications" Dec 22 2004 07:46PM
Augusto Paes de Barros (apbarros gmail com)
I believe that one of the conditions that need to exist to enable this
kind of attack is being overlooked. The paper says that the user has
to be logged on the application. Of course that this is possible and
even plausible in lots of situations, but let's remember that it
creates a time window for ...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus