Win a copy of Secure Financial Transactions with Ansible, Terraform, and OpenSCAP this week in the Cloud/Virtualization forum!
  • Post Reply Bookmark Topic Watch Topic
  • New Topic
programming forums Java Mobile Certification Databases Caching Books Engineering Micro Controllers OS Languages Paradigms IDEs Build Tools Frameworks Application Servers Open Source This Site Careers Other Pie Elite all forums
this forum made possible by our volunteer staff, including ...
  • Campbell Ritchie
  • Ron McLeod
  • Paul Clapham
  • Jeanne Boyarsky
  • Bear Bibeault
  • Rob Spoor
  • Henry Wong
  • Liutauras Vilda
Saloon Keepers:
  • Tim Moores
  • Carey Brown
  • Stephan van Hulst
  • Tim Holloway
  • Piet Souris
  • Frits Walraven
  • Himai Minh
  • Jj Roberts

session fixation

Posts: 5
  • Mark post as helpful
  • send pies
    Number of slices to send:
    Optional 'thank-you' note:
  • Quote
  • Report post to moderator
Please help in implementing session fixation in java.

A countermeasure against session fixation is to generate a new session
identifier (SID) on each request. Thus, although attacker may trick a user into accepting a known SID, the SID will be invalid when attacker attempts to re-use the SID. Implementation of such a system is simple, as demonstrated by the following:

� Get previous Session Identifier OLD_SID from HTTP request.
� If OLD_SID is null, empty, or no session with SID=OLD_SID exists, create a
New session.
� Generate new session identifier NEW_SID with a secure random number
� Let session be identified by SID=NEW_SID (and no longer by SID=OLD_SID)
� Transmit new SID to client.

Posts: 13459
Android Eclipse IDE Ubuntu
  • Mark post as helpful
  • send pies
    Number of slices to send:
    Optional 'thank-you' note:
  • Quote
  • Report post to moderator
You also keep the same session but include a request counter. eg in each request the person needs to increment the counter by one (which is done via the app, not manually by the client) and the number is also kept on the server side. If they disagree or get out of synch the session is discarded.
You will always be treated with dignity. Now, strip naked, get on the probulator and hold this tiny ad:
SKIP - a book about connecting industrious people with elderly land owners
    Bookmark Topic Watch Topic
  • New Topic