Security Paper: Session Fixation Vulnerability in Web-based Applications

From: Mitja Kolsek (ACROS Lists) (lists@ACROS.SI)
Date: 12/18/02

  • Next message: Steve Midgley: "Re: Session Fixation Vulnerability in Web-based Applications"
    Date:         Wed, 18 Dec 2002 15:01:25 +0100
    From: "Mitja Kolsek (ACROS Lists)" <lists@ACROS.SI>
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    ACROS Security is pleased to announce the publication of a security paper
    about a new class of attacks on web-based applications that we named
    "session fixation" attacks. The paper is available at

            [ http://www.acros.si/papers/session_fixation.pdf ]

    and could be useful to all web applications developers and security
    analysts. We will appreciate any feedback you might provide.

    Mitja Kolsek

    ACROS, d.o.o.
    Stantetova 4, SI - 2000 Maribor, Slovenia
    web: http://www.acros.si
    e-mail: mitja.kolsek@acros.si

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Delivery co-sponsored by TruSecure Corporation
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Demonstrate your knowledge and understanding of core IT Security, become
    TICSA certified.

    Are you responsible for IT security in job function, but not necessarily
    in title? Do you want to prove your IT security knowledge and increase
    opportunities? Interested? Visit;

    http://www.trusecure.com/solutions/certifications/ticsa/

    for more information.
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo



    Relevant Pages

    • Re: Pelosi & Reid Will Not Like Progress Cited in Iraq Quarterly Report
      ... This is from 4 pages, less than 10 percent, of the report. ... Reid has called General Petraeus a liar for saying progress had been made in Iraq, and more recently he has called Petraeus and outgoing chairman of the Joint Chiefs,Marine Gen. ... Assessment of the Security Environment— ... the frequency and intensity of attacks on the ...
      (soc.retirement)
    • Re: Pelosi & Reid Will Not Like Progress Cited in Iraq Quarterly Report
      ... This is from 4 pages, less than 10 percent, of the report. ... Reid has called General Petraeus a liar for saying progress had been made in Iraq, and more recently he has called Petraeus and outgoing chairman of the Joint Chiefs,Marine Gen. ... Assessment of the Security Environment— ... the frequency and intensity of attacks on the ...
      (soc.retirement)
    • Re: Cracking WEP and WPA keys
      ... SecurityFocus wi-fi security mailing list. ... >>802.11G PCMCIA card, and the Linux server was running Samba to talk to ... >>Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • RE: Vulnerabilites in new laws on computer hacking
      ... This damages all security professionals. ... Vulnerabilites in new laws on computer hacking ... "advanced societies" will have no clue about how remote computer attacks ...
      (Bugtraq)
    • [Full-Disclosure] Security & Obscurity: First-time attacks and lawyer jokes
      ... I've taught semester courses on the Law of Cybersecurity twice in ... the people in OMB who were responsible for computer security for the ... where the secrecy approach holds true in a networked world. ... emphasize is the number of attacks. ...
      (Full-Disclosure)