[VulnWatch] Security Paper: Session Fixation Vulnerability in Web-based Applications
From: Mitja Kolsek (ACROS Lists) (lists@acros.si)
Date: 12/18/02
- Previous message: Michal Zalewski: "[VulnWatch] RAZOR advisory: Linux 2.2.xx /proc/<pid>/mem mmap() vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Mitja Kolsek (ACROS Lists)" <lists@acros.si> To: <bugtraq@securityfocus.com>, <vulnwatch@vulnwatch.org>, <NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM> Date: Wed, 18 Dec 2002 15:01:25 +0100
ACROS Security is pleased to announce the publication of a security paper
about a new class of attacks on web-based applications that we named
"session fixation" attacks. The paper is available at
[ http://www.acros.si/papers/session_fixation.pdf ]
and could be useful to all web applications developers and security
analysts. We will appreciate any feedback you might provide.
Mitja Kolsek
ACROS, d.o.o.
Stantetova 4, SI - 2000 Maribor, Slovenia
web: http://www.acros.si
e-mail: mitja.kolsek@acros.si
- Next message: iDEFENSE Labs: "[VulnWatch] iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)"
- Previous message: Michal Zalewski: "[VulnWatch] RAZOR advisory: Linux 2.2.xx /proc/<pid>/mem mmap() vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|