Session Hijacking
Session Hijacking
Tarun Lall
State Management
No Standards for Maintaining State Session Tracking and State information at Client
Session Identifiers Should Be Unique Session Identifiers Should Not be Guessable Session Identifiers Should Be Independent
References
Web hacking Attacks and Defense by Stuart McClure, Saumil Shah, Shreeraj Shah http://www.ftponline.com/javapro/2004_01/m agazine/columns/proshop/default_pf.aspx http://www.iss.net/security_center/advice/Exp loits/TCP/session_hijacking/default.htm http://staff.washington.edu/dittrich/talks/qsmsec/script.html