William has control over the generation of session identifiers
William has control over the generation of session identifiers
OWASP SCP
58,59
OWASP ASVS
3.7.1
OWASP AppSensor
SE2
CAPEC
-
SAFECODE
28
In general use the server or framework’s own session management controls, rather than creating custom code. The application should only recognize these session identifiers as valid, and the session identifier creation must always be done on a trusted system (e.g. server-side).
OWASP ASVS (4.0): 3.7.1
OWASP SCP: 58,59
OWASP Appsensor: SE2
Safecode: 28
ASVS V3.7 - Defenses Against Session Management Exploits
No suitable mappings were found.
Password Guessing/Brute Force Attacks