Web Server Predictable Session ID Vulnerability
-
Couldn’t find the topic related to subject if it does exist, post me a link.
Does anyone know the solution to solve the following vulnerability?Session cookies are:
1: Set-Cookie: _lscache_vary=237bda7cfcf92894df7a4f0dbc1947af
2: Set-Cookie: _lscache_vary=237bda7cfcf92894df7a4f0dbc1947af
3: Set-Cookie: _lscache_vary=237bda7cfcf92894df7a4f0dbc1947af
4: Set-Cookie: _lscache_vary=237bda7cfcf92894df7a4f0dbc1947af
5: Set-Cookie: _lscache_vary=237bda7cfcf92894df7a4f0dbc1947afPercentage of common characters among subsequent cookies: 100%
The session ID can be trivially guessed after only a limited number of attempts. If this issue is successfully exploited, then it may be possible for an attacker to obtain the cookie-based authentication credentials for legitimate users, allowing unauthorized access to the vulnerable application.
- The topic ‘Web Server Predictable Session ID Vulnerability’ is closed to new replies.