Guessable Session ID (Web)


1.0.0 bởi hpAndro
Jul 23, 2021

Về Guessable Session ID

Cuộc tấn công dự đoán phiên tập trung vào dự đoán giá trị ID phiên

The session prediction attack focuses on predicting session ID values that permit an attacker to bypass the authentication schema of an application. By analyzing and understanding the session ID generation process, an attacker can predict a valid session ID value and get access to the application.

n the first step, the attacker needs to collect some valid session ID values that are used to identify authenticated users. Then, they must understand the structure of session ID, the information that is used to create it, and the encryption or hash algorithm used by the application to protect it. Some bad implementations use sessions IDs composed by username or other predictable information, like timestamp or client IP address. In the worst case, this information is used in clear text or coded using some weak algorithm like base64 encoding.

Thông tin thêm Ứng dụng

Phiên bản mới nhất

1.0.0

Được tải lên bởi

Nilton Schneider Jr.

Yêu cầu Android

Android 6.0+

Báo cáo

Gắn cờ là không phù hợp

Hiển thị nhiều hơn

Use APKPure App

Get Guessable Session ID old version APK for Android

Tải về

Use APKPure App

Get Guessable Session ID old version APK for Android

Tải về

Guessable Session ID Thay thế

Xem thêm từ hpAndro

Phát hiện