|
Session tokens should never be transmitted in the URL, because this provides a simple vehicle for session fixation attacks and result in tokens appearing in numerous logging mechanisms. In some cases, developers use this technique to implement sessions in browser that have cookies disabled. However, a better means of achieving this is to use POST requests for all navigation and store tokens in a hidden field of an HTML form.
จากหนังสือ The Web Application Hacker's handbook 2
จากคุณ |
:
^pop^
|
เขียนเมื่อ |
:
วันพ่อแห่งชาติ 54 11:28:41
|
|
|
|
|