Penetration Testing mailing list archives

Re: [PEN-TEST] HTTP Secure Session State Management


From: Drew Simonis <dsimonis () FIDERUS COM>
Date: Thu, 28 Dec 2000 10:21:08 -0500

"Edwards, David (JTD)" wrote:


To attempt to bring this back "on-topic" a bit :-)

Has anyone looked at network penetration using WEBDAV/NDSDAV?
Or even seen a security evaluation of WEBDAV/NDSDAV?


Also more on topic... Don't PHP4 and MS ASP have some built in
session management features?  Has anyone hacked these methods
enough to understand what they do?


Current thread: