Unlimited WordPress themes, plugins & video downloads!

Research

Research – session_fixation.pdf

Session Fixation Vulnerability in Web-based Applications – Many web-based applications employ some kind of session management to create a user friendly environment. Sessions are stored on a server and associated with respective users by sessions identifiers (IDs). Naturally session IDs present an attractive target for attackers, who, by obtaining them, effectively hijack users’ identities. Knowing that, web servers are employing techniques for protecting session IDs from three classes of attacks: interception, prediction, and brute force attacks. This paper reveals a fourth class of session attacks against session IDs: session fixation attacks.

 

You can download it from the following link: https://packetstormsecurity.com/files/download/30619/session_fixation.pdf

Source: https://packetstormsecurity.com/files/30619/session_fixation.pdf.html

Related posts
Research

Research - RiseCON 2014 Call For Papers

Research

Research - Rooted CON 2012 Call For Papers

Research

Research - RSA Asymmetric Polymorphic Shellcode

Research

Research - RVAsec 2017 Call For Papers

Sign up for our Newsletter and
stay informed