Forums Register Login

HTTP Sessions behavior

+Pie Number of slices to send: Send
How does a Container like Tomcat identify a client as being 'the same client between requests'? Is this by sessionID?

If the client keeps two browser windows open that both visit the same servlet (therefore two threads exist), how come the exact same sessionID is being exchanged (and therefore causing multithreading problems)? Why does the Container treat the client as the same regardless of browser window?

Another question:
It is possible to steal someone's HTTP session, right? I have read online that certain vBulletin boards were exploited by some session exploit (I don't know of the details).
Is it also possible to steal someone's request?
Talk sense to a fool and he calls you foolish. -Euripides A foolish tiny ad:
a bit of art, as a gift, that will fit in a stocking
https://gardener-gift.com


reply
reply
This thread has been viewed 598 times.
Similar Threads
Cookies
Url Rewriting in new browser window
Session management ambiguity
same session when press ctrl + N in IE6
Is session object thread safe.
More...

All times above are in ranch (not your local) time.
The current ranch time is
Apr 16, 2024 09:43:15.