Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: IIS session cookies

From: Forrest Lee Andrews <lee.andrews(at)cox.net>
Date: Sat Dec 07 2002 - 23:00:23 EST

  1. no, you can't specify the sessionID length.
  2. The session-ID is agnostic as to SSL. If SSL is enabled, all traffic, including the sessionID will be encrypted. Otherwise, it will be in cleartext.

-----Original Message-----
From: securityarchitect@hush.com [mailto:securityarchitect@hush.com] Sent: Saturday, December 07, 2002 8:52 PM To: cairnsc@securityfocus.com; kspett@spidynamics.com Cc: webappsec@securityfocus.com; secprog@securityfocus.com; mikehow@microsoft.com
Subject: Re: IIS session cookies

Not knowing much about Windows, ASP or .NET, does IIS allow you to

Set sessionID length ? If so how ?

How does it move users from a non-SSL session to a SSL session (ie does a new value get set) ?

On Fri, 06 Dec 2002 07:18:35 -0800 Kevin Spett <kspett@spidynamics.com> wrote:
>From http://www.securiteam.com/windowsntfocus/6C00L003GA.html:
/
>aspwsm.asp:

Concerned about your privacy? Follow this link to get FREE encrypted email: https://www.hushmail.com/?l=2

Big $$$ to be made with the HushMail Affiliate Program: https://www.hushmail.com/about.php?subloc=affiliate&l=427 Received on Sat Dec 7 23:49:57 2002

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:46 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library