Session fixation – the forgotten vulnerability?
Autor(en):
Zusammenfassung
The term 'Session Fixation vulnerability' subsumes issues in Web applications that under certain circumstances enable the adversary to perform a session hijacking attack through controlling the victim's session identifier value. We explore this vulnerability pattern. First, we give an analysis of the root causes and document existing attack vectors. Then we take steps to assess the current attack surface of Session Fixation. Finally, we present a transparent server-side method for mitigating vulnerabilities.
- Vollständige Referenz
- BibTeX
Schrank, M., Braun, B., Johns, M. & Posegga, J.,
(2010).
Session fixation – the forgotten vulnerability?.
In:
Freiling, F. C.
(Hrsg.),
Sicherheit 2010. Sicherheit, Schutz und Zuverlässigkeit.
Bonn:
Gesellschaft für Informatik e.V..
(S. 341-352).
@inproceedings{mci/Schrank2010,
author = {Schrank, Michael AND Braun, Bastian AND Johns, Martin AND Posegga, Joachim},
title = {Session fixation – the forgotten vulnerability?},
booktitle = {Sicherheit 2010. Sicherheit, Schutz und Zuverlässigkeit},
year = {2010},
editor = {Freiling, Felix C.} ,
pages = { 341-352 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Schrank, Michael AND Braun, Bastian AND Johns, Martin AND Posegga, Joachim},
title = {Session fixation – the forgotten vulnerability?},
booktitle = {Sicherheit 2010. Sicherheit, Schutz und Zuverlässigkeit},
year = {2010},
editor = {Freiling, Felix C.} ,
pages = { 341-352 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 978-3-88579-264-2
ISSN: 1617-5468
Datum: 2010
Sprache:
(en)
(en)
Typ: Text/Conference Paper

