Can a session be rigged?

I need to check all my asp code to prevent SQL injection.

Should I also check the session object?

How can a session be captured?

Thanks!

+5
source share
4 answers

Session can be captured. If I remember correctly, Classic ASP only supports cookie-based session identifiers. If someone was able to steal this cookie (wired contact), he can get the same session as a legitimate user.

? . , , , "" ( ), . - Session, .

+3

SQL, SQL- . - . cookie HTTPS. ( ) ().

+3

, . , , : " ?" , sql-.

, , sql- , sql. sql- , , , SQL-.

, , sql-.

+1

. cookie. , . , SQL-, .

+1

All Articles