3 ms·
If your session Ids were short enough to be guessed then you were doing it wrong. The simplest thing to do is just use a unique GUID as a session id but a suffi
by AndrewStephens 4y ago
If your session Ids were short enough to be guessed then you were doing it wrong. The simplest thing to do is just use a unique GUID as a session id but a sufficiently large random number would do just as well.
- GoToRO 4y agoAt first they were short, and you could get one to see the format and then just try to enumerate some random numbers around that value. Without rate limit for the requests, it worked.