Posted by howa on 06/11/07 15:10
> - use very short session life time
> - force user to login again before doing something important
I found that many Yahoo! or Google only use SSL during authentication
only, the rest of the services are provided by plain HTTP only...
really interested in how to prevent session hijacking, especailly from
neighbor hosts with the SAME IP, really difficult...
Navigation:
[Reply to this message]
|