11.07.2015 Views

SAP: Session (Fixation) Attacks and Protections - Black Hat

SAP: Session (Fixation) Attacks and Protections - Black Hat

SAP: Session (Fixation) Attacks and Protections - Black Hat

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

WebLogic HTTPS Enforcement (1)• web.xml:SSL not requiredNONE• HTTPS is not enforced by WebLogic– User dependent: “http://” or “https://” links– NONE: HTTPS not enforced (HTTP allowed)– CONFIDENTIAL: Ensure confidentiality– INTEGRAL: Ensure integritySSLTLSCopyright © 2011 Taddong S.L. www.taddong.com40

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!