3 ms·
Session IDs were short, so it was easy to randomly guess them. You would get access to some random account. Also randomly generating them would result in colis
by GoToRO 4y ago
Session IDs were short, so it was easy to randomly guess them. You would get access to some random account.
Also randomly generating them would result in colisions if you had a lot of traffic.
- AndrewStephens 4y agoIf your session Ids were short enough to be guessed then you were doing it wrong. The simplest thing to do is just use a unique GUID as a session id but a sufficiently large random number would do just as well.
- GoToRO 4y agoAt first they were short, and you could get one to see the format and then just try to enumerate some random numbers around that value. Without rate limit for the requests, it worked.