4 ms·
I think of the following: - store only session ID in cookie - regenerate session ID upon privilege escalation (login, what else?) - destroy session upon logo
by nchelluri 11y ago
I think of the following:
- store only session ID in cookie
- regenerate session ID upon privilege escalation (login, what else?)
- destroy session upon logout
That being the case, is this really capable of doing much damage? Especially once you enable HSTS.
- Eridrus 11y agoThis is still vulnerable to the same kinds of attacks you can do with login CSRF: http://seclab.stanford.edu/websec/csrf/csrf.pdf http://seclab.stanford.edu/websec/csrf/csrf.pdf Though the attack scenarios for that are always very tenuous.