메뉴 건너뛰기




Volumn 8, Issue 5, 2010, Pages 48-56

Session management vulnerabilities in today's web

Author keywords

security and privacy; session management; Web application security

Indexed keywords

CYBER-ATTACKS; SECURITY AND PRIVACY; SENSITIVE DATAS; SESSION MANAGEMENT; WEB APPLICATION DESIGN; WEB APPLICATION SECURITY;

EID: 77958136467     PISSN: 15407993     EISSN: None     Source Type: Journal    
DOI: 10.1109/MSP.2010.114     Document Type: Article
Times cited : (24)

References (9)
  • 2
    • 77958137751 scopus 로고    scopus 로고
    • Certified lies: Detecting and defeating government interception attacks against SSL
    • Apr.
    • C. Soghoian and S. Stamm, "Certified Lies: Detecting and Defeating Government Interception Attacks against SSL," Social Science Research Network, Apr. 2010; http://files.cloudprivacy.net/ssl-mitm.pdf.
    • (2010) Social Science Research Network
    • Soghoian, C.1    Stamm, S.2
  • 3
  • 5
    • 77958134994 scopus 로고    scopus 로고
    • Weak randomness: Part i-linear congru- ential random number generators
    • C. Anley, "Weak Randomness: Part I-Linear Congru- ential Random Number Generators," Next Generation Security Software, 2007; www.ngssoftware.com/Librar- ies/Documents/02-07-Weak-Randomness.sfl b.ashx.
    • (2007) Next Generation Security Software
    • Anley, C.1
  • 6
    • 77958145375 scopus 로고    scopus 로고
    • Cross site scripting
    • "Cross Site Scripting," Web Application Security Con- sortium, 2009; www.webappsec.org/projects/threat/ classes/cross-site-scripting.shtml.
    • (2009) Web Application Security Con- Sortium
  • 7
    • 77958120972 scopus 로고    scopus 로고
    • Session fixation vulnerability in web- based applications
    • Dec.
    • M. Kolšek, "Session Fixation Vulnerability in Web- Based Applications," Acros Security, Dec. 2002; www. acrossecurity.com/papers/ session-fi xation.pdf.
    • (2002) Acros Security
    • Kolšek, M.1
  • 8
    • 84948613344 scopus 로고    scopus 로고
    • OWASP testing guide v3
    • Nov.
    • "OWASP Testing Guide v3," Open Web Application Security Project Foundation, Nov. 2008; www.owasp. org/index.php/OWASP-Testing-Guide-v3-Table- of-Contents.
    • (2008) Open Web Application Security Project Foundation
  • 9
    • 77949879017 scopus 로고    scopus 로고
    • Automatic creation of SQL injection and cross-site scripting attacks
    • IEEE CS Press
    • A. Kiezun et al., "Automatic Creation of SQL Injection and Cross-Site Scripting Attacks," Proc. 31st Int'l Conf. Software Eng., IEEE CS Press, 2009, pp. 199-209.
    • (2009) Proc. 31st Int'l Conf. Software Eng. , pp. 199-209
    • Kiezun, A.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.