Secure Programming
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: ASP/ASP.NET Session IDs Mar 17 2005 11:41PM
Steven DeFord (security willworker gmail com)
On Thu, 17 Mar 2005 18:35:02 -0500, Darren Bounds
<dbounds (at) intrusense (dot) com [email concealed]> wrote:
> Based on your question it sounds like you're missing an important step
> in the process. The 16-byte cookie string is not merely an encrypted
> 32-bit unsigned integer, but rather the 32-bits combined with X bits of
...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus