Quantcast
Channel: Security
Viewing all articles
Browse latest Browse all 4737

Session Replay in ASP.Net Forms authentication

$
0
0

Hello,

During Penetration testing of my ASP.Net web forms application, following issues has been reported:-.

1. ASP Sessions can be replayed.

I am using forms authentication with below mark-up

<authentication mode="Forms">
      <forms name=".ASPXAUTH" loginUrl="~\Login.aspx" defaultUrl="~\Login.aspx" slidingExpiration="true" timeout="90" path="/" />
    </authentication>

Can any-one pls help me how i can stop session replay (aspxauth session from some previous sessions has been reused). Thanks.


Viewing all articles
Browse latest Browse all 4737

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>