reusing existing sessionid in cookieless session management

T

Toro

Hi,

I have found some information about a potential security flaw in
cookieless session management. I am sure that the issue is well known to the
community because it was reported over 2 years ago.

[http://builder.com.com/5100-6387-1044869.html]

Since this report nothing was apparently done to fix the issue because
the hole still exists in ASP.NET 1.1.

Two questions then:

1. Is there any obvious and objective reason for that this issue cannot be
easily fixed by not allowing the asp.net engine to create a new session with
user-supplied id? Does it break the cookieless session model in some other
places? If not, will the issue be fixed in asp.net 2.0?

2. Does using the https solve the issue?

Thanks in advance for any information.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

Forum statistics

Threads
473,769
Messages
2,569,580
Members
45,054
Latest member
TrimKetoBoost

Latest Threads

Top