-
Book Overview & Buying
-
Table Of Contents
The Web Application Hacker's Handbook
By :
The defensive measures that web applications must take to prevent attacks on their session management mechanisms correspond to the two broad categories of vulnerability that affect those mechanisms. To perform session management in a secure manner, an application must generate its tokens in a robust way and must protect these tokens throughout their life cycle from creation to disposal.
The tokens used to reidentify a user between successive requests should be generated in a manner that does not provide any scope for an attacker who obtains a large sample of tokens from the application in the usual way to predict or extrapolate the tokens issued to other users.
The most effective token generation mechanisms are those that:
In principle, any item of arbitrary...
Change the font size
Change margin width
Change background colour