Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Session Fixation

From: Information Security <InformationSecurity(at)federatedinv.com>
Date: Mon Mar 31 2003 - 08:19:14 EST


I recently visited a site (I think it might have been my bank) where they actually had an option for "additional security" where you could link the session to your IP address. I was impressed, and thought it was a great option, but I'm not sure how many non-security folks would. But the nice thing was that the communications--calling it an "additional security feature" rather than something very technical.

There are, IMHO, at least two other mitigation strategies, or points to consider:

First, make sure applications have a "logout" option, and train users to use it when they're done. It's a mitigation strategy for this and other session vulneraiblities (XSS, etc) to at least reduce the window of opportunity.

Second, make sure the account password change page (and hint pages, if applicable) require the user to supply the old password as well as the new. Prevents the hijacked session from changing the password and essentially creating the back door.

-----Original Message-----
From: Gary Gwin [mailto:websec@cafesoft.com] Sent: Thursday, March 27, 2003 3:25 PM
To: webappsec@securityfocus.com
Subject: Re: Session Fixation

Thanks for posting, this is an excellent article.

One cavaet is with respect to binding the session ID to the browser's network address. There are some proxy servers that swap IP addresses between HTTP requests. In this case, binding to the exact IP address can cause a valid session to be orphaned.

Gary

Do you need help?X

St. Clair, James wrote:
> FYI - for those who have not seen it..

-- 

Gary Gwin
http://www.cafesoft.com

*****************************************************************
*                                                               *
*   The Cafesoft Access Management System, Cams, is security    *
*   software that provides single sign-on authentication and    *
*   centralized access control for Apache, Tomcat, and custom   *
*   resources.                                                  *
*                                                               *
*****************************************************************
Received on Mon Mar 31 10:37:38 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:49 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library