|
|
|
|
broken authentication and session management vulnerabilities
|
|
|
|
|
|
|
|
نویسنده
|
aljoaey hanan ,almutawa khawla ,alabdali ruyuf ,m.ibrahim dina ,m.ibrahim dina
|
|
منبع
|
the isc international journal of information security - 2021 - دوره : 13 - شماره : 3 - صفحه:11 -19
|
|
چکیده
|
Web application protection is today's most important battleground between the victim, intruder, and web service resource. user authentication tends to be critical when a legitimate user of the web application abruptly ends the contact while the session is still active, and an unauthorized user chooses the same session to gain access to the device. for many corporations, risk detection is still a problem. in other cases, it is a usual way of operating that provides the requisite protection to keep the product free of weaknesses. using various types of software to identify dierent security vulnerabilities assists both developers and organizations in securely launching applications, saving time and money. dierent combinations of tools have been seen to enhance protection in recent years, but it has not been possible to combine the types of tools available on the market until the writing of this report. this paper aims to clarify vulnerabilities in broken authentication and session management. it is worth noting that if the creator practices the preventive techniques outlined in this article, the chances of exploitation being discussed are reduced. this paper revealed that the most powerful ways to exploit the broken authentication and session management vulnerabilities of the web application in those domains are session misconguration assault and cracking/ guessing weak passwords. correspondingly included techniques to defend authentication and the most important is using a robust encryption system, setting password rules, and securing the session id. © 2020 isc.
|
|
کلیدواژه
|
broken authentication ,session management ,credential stuffing ,password spraying
|
|
آدرس
|
qassim university, college of computer, department of information technology, saudi arabia, qassim university, college of computer, department of information technology, saudi arabia, qassim university, college of computer, department of information technology, saudi arabia, qassim university, college of computer, department of information technology, saudi arabia. tanta university, faculty of engineering, computers and control engineering deptartment, egypt, qassim university, college of computer, department of information technology, saudi arabia. tanta university, faculty of engineering, computers and control engineering deptartment, egypt
|
|
پست الکترونیکی
|
dina.mahmoud@f-eng.tanta.edu.eg
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Authors
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|