WebApp Sec mailing list archives

Re: Whitepaper "SESSION RIDING - A Widespread Vulnerability in Today's Web Applications"


From: "Sverre H. Huseby" <shh () thathost com>
Date: Tue, 21 Dec 2004 08:20:33 +0100

[Elihu Smails]

|   Sessions should track the remote IP address of the client at a
|   minimum, so that this problem could go away.

Unfortunately, checking IP addresses won't solve the Session Riding /
Web Trojan problem, as the request is coming from the victim's
computer.


Sverre.


Current thread: