会话(web分析)
利用
计算机安全
妥协
计算机科学
Web应用程序
互联网隐私
万维网
政治学
法学
作者
Corrado Aaron Vlsaggio,Lorenzo Convertito Blasio
出处
期刊:IEEE Security & Privacy
[Institute of Electrical and Electronics Engineers]
日期:2010-06-23
卷期号:8 (5): 48-56
被引量:31
摘要
Many cyber attacks exploit session management vulnerabilities that allow recognition of attackers as valid website users. Under these fake identities, attackers can steal sensitive data, alter private settings, and compromise website structure and content. This article describes Web application design flaws that could be exploited for session management attacks and discusses these flaws' current prevalence.
科研通智能强力驱动
Strongly Powered by AbleSci AI