Help needed ASAP, Security issue!

C

Chris

I have a security consultant group bashing Microsoft byt stating that the way
IIS handles Session ID is flawed. They're asking me to, once my users hit the
first asp page pre-authentication, to then destroy that session id
(ASPSESSIONID) and re-assign one. How can that be done? It's read only. And I
keep stating that this is in 128-bit SSL where the header is encrypted. Since
my code is coming from COM+ (VB6.0) and I'm recycling to the same 'asp' page,
I can not see a way to abandon the session, since I have items in the session
prior to login.
Is there a better approach?
Is there a way in COM+ VB to trick it by giving it a new page to reset the
session? I can abandon the session but I won't get a new ID since the page is
not re-rendered. And during that grey area I'm setting more session values.

I'm running on a Win2K server w/SP4 and the secureaspsessionid patch.

thanx!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

No members online now.

Forum statistics

Threads
473,754
Messages
2,569,522
Members
44,995
Latest member
PinupduzSap

Latest Threads

Top