Re: how to prevent users from sharing their cookieless session id?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



this is the main disadvantage of using the url for session id. there are no
easy fixes. you can change the url session id on every page flip, and not
honor old session ids. this has the side effect if the users refreshes, they
have to login again. a better approach is to store session id in a hidden
field, and avoid redirects.

-- bruce (sqlwork.com)



"Liam" <Liam@xxxxxxxx> wrote in message
news:OZ9JLLGRGHA.4956@xxxxxxxxxxxxxxxxxxxxxxx
We are using cookieless sessions, and so the URL shows the session id,
e.g. http://ourdomain.com(ixbradnm5qmdfwikrt1mcfi3)/somepage.aspx.

When a user comes to our main page, they have to provide a username and
password. We authenticate the username and password against our database,
and if they match, we let the user in the door, so to speak, by assigning
session variables with a new visitid, and a unique visitorid, and then
redirecting the user to our internal pages.
We want each user's session to be unique to the user.

How can we stop the practice where a user, who has made it through the
door, pastes an inner page's URL into an email message and sends it to his
or her colleagues (when they find something they'd like to share, for
example)? If the session hasn't timed out, the colleagues who receive the
email and click on the link get access to the original user's session and
personal information, such as last 10 items viewed, email address,
interests, and so forth, etc.
Thanks
Liam


.



Relevant Pages

  • Actual Play - Pathfinder: Rise of the Runelords (Session Five)
    ... (A short session this week, owing to a late start and a sleepy DM.) ... ("A stout oaken door" became a bit of a gag in this session, ... Tharl turned to his companions and voiced his fears that the room ... Detect magic revealed that the scroll and the metal rod - obviously some ...
    (rec.games.frp.dnd)
  • how to prevent users from sharing their cookieless session id?
    ... We authenticate the username and password against our database, and if they match, we let the user in the door, so to speak, by assigning session variables with a new visitid, and a unique visitorid, and then redirecting the user to our internal pages. ... How can we stop the practice where a user, who has made it through the door, pastes an inner page's URL into an email message and sends it to his or her colleagues? ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: how to prevent security violation when users share URL with cookieless session id?
    ... I recently even saw a web page with a cookieless session indexed on google:) ... colleagues click on the link, the colleagues end up piggybacking on ... validation we perform against our registration database? ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Comparing proportions?
    ... *In each session, the part of the session they spend working with one out ... between teachers, between methods and possibly also an interaction between ... The problem was posed by one of my colleagues who has studied "teacher ... At first it sounded like some ANOVA setup, ...
    (sci.stat.consult)
  • Comparing proportions?
    ... *In each session, the part of the session they spend working with one out ... What I would like to do is to see if there are any significant differences ... between teachers, between methods and possibly also an interaction between ... The problem was posed by one of my colleagues who has studied "teacher ...
    (sci.stat.consult)