11.07.2015 Views

SAP: Session (Fixation) Attacks and Protections - Black Hat

SAP: Session (Fixation) Attacks and Protections - Black Hat

SAP: Session (Fixation) Attacks and Protections - Black Hat

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Session</strong> <strong>Fixation</strong> Discovery SummaryHTTP request (w/o session ID)HTTP response (session ID)AuthentificationIDID(pre-authentication)Pen-testerResponse (post-authentication)HTTP request (token)<strong>Session</strong> specific dataIDWeb-AppHTTP request (token)...<strong>Session</strong> trackingAuthentication or any application privilege level changeCopyright © 2011 Taddong S.L. www.taddong.com14

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!