WebApp Sec mailing list archives

Re: Cookie not expiring...


From: Thomas Chiverton <thomas.chiverton () bluefinger com>
Date: Wed, 17 Aug 2005 09:28:55 +0100

On Tuesday 16 August 2005 18:08, spawn security wrote:
FormsAuthentication.SignOut method works by returning a Set-Cookie

I would hope sesssion.Abandon() kills the server side session too.
Have you tried stealing the cookie ?

-- 

Tom Chiverton 
Advanced ColdFusion Programmer


Current thread: