Ver Mensaje Individual
  #25 (permalink)  
Antiguo 18/03/2013, 14:11
Avatar de Ronin46
Ronin46
 
Fecha de Ingreso: junio-2009
Mensajes: 398
Antigüedad: 14 años, 10 meses
Puntos: 8
Respuesta: Duda session hijacking

Este es el enlace que andaba buscando: http://shiflett.org/articles/session...ing#comment-21

Cita:
There may need to be some tweaking to allow for near-simultaneous requests both of which are legitimate. I addressed it by comparing the request token presented in the cookie with not just "last-issued" token but also "second-last issued token", and imposed a limitation that the time-difference between the two must be no more than 3 seconds – otherwise the 2 requests are not deemed near-simultaneous and the server kills the session under the suspicion that legitimate requests are accompanied by malicious requests.
__________________
http://www.controldegastos.com, acepto sugerencias para el sitio.
Repetir conmingo: "tengo que dedicar más tiempo a gozar de placer"