473,657 Members | 2,535 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

Help needed ASAP, Security issue!

I have a security consultant group bashing Microsoft byt stating that the way
IIS handles Session ID is flawed. They're asking me to, once my users hit the
first asp page pre-authentication, to then destroy that session id
(ASPSESSIONID) and re-assign one. How can that be done? It's read only. And I
keep stating that this is in 128-bit SSL where the header is encrypted. Since
my code is coming from COM+ (VB6.0) and I'm recycling to the same 'asp' page,
I can not see a way to abandon the session, since I have items in the session
prior to login.
Is there a better approach?
Is there a way in COM+ VB to trick it by giving it a new page to reset the
session? I can abandon the session but I won't get a new ID since the page is
not re-rendered. And during that grey area I'm setting more session values.

I'm running on a Win2K server w/SP4 and the secureaspsessio nid patch.

thanx!
Aug 18 '05 #1
0 980

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

8
5463
by: baustin75 | last post by:
Posted: Mon Oct 03, 2005 1:41 pm Post subject: cannot mail() in ie only when debugging in php designer 2005 -------------------------------------------------------------------------------- Hello, I have a very simple problem but cannot seem to figure it out. I have a very simple php script that sends a test email to myself. When I debug it in PHP designer, it works with no problems, I get the test email. If
8
1633
by: Anantha | last post by:
Hi All, We are haveing 4 DB's in our company, and presently we used to take offline backup on once in a week, we knew we cant recover last-in-time data. But we would like to shift to some new technique which saves time, sapce & last-in-time recover. we heard about the online backups and incremental backups, what are they actually, what is the differences. Here the main requirements is recovering the with- miniual loss and 24x7...
0
908
by: David | last post by:
I need to send e-mail from within an ASP.NET web page. Having problem. Need assistance Have two installation scenarios: 1) local machine (development machine connected to network); 2) network server. I use Mail.MailMessage class within ASP.NET page to send e-mail from the web site pages On local machine - have IIS installed; SMTP Service installed and running; When I access web app from this development machine (localhost), I can...
7
1245
by: Roshawn Dawson | last post by:
Hi, I have an xslt file located in the root directory. It is used by an aspx pages in both the root directory and a subdirectory. But for some strange reason, the aspx page in the subdirectory can neither locate the xslt file or the css file needed to get the desired results. What's the problem? Can anyone help me? Thanks, Roshawn
5
1606
by: Tiraman | last post by:
Hi , i have the A.dll in my GAC (only one occurrence) and after i deleted it from the GAC i saw that it still working . so i did IISRESET and now it throw an error . can we define the time out that the dll stay in the memory ? lets say that if no one access the dll for 60 sec it will be removed from the memory and only in the next time
5
1127
by: Brian Henry | last post by:
If i have a text box and want to input a text string into it then use my help files search to look for the inputted text from the application how would i do that? thanks
2
1438
by: lili | last post by:
I've had to take the site offline to work on it so I can see what's going on. Can anyone help? http://www.mauidesign.com/mauikaitest/index.html Two problems: 1. IE users (I think those on Windows 2000) are experiencing browser crashes, and in one case a viewer's whole system actually crashed.
15
2569
by: Jay | last post by:
I have a multi threaded VB.NET application (4 threads) that I use to send text messages to many, many employees via system.timer at a 5 second interval. Basically, I look in a SQL table (queue) to determine who needs to receive the text message then send the message to the address. Only problem is, the employee may receive up to 4 of the same messages because each thread gets the recors then sends the message. I need somehow to prevent...
4
2212
by: Brad Isaacs | last post by:
I am working with ASP.NET 2.0 and using an SQL Server 2000 database. I am using Visual Studio 2005 and developing on my Local machine. I am working with Login controls ASP.Configuration, I wanted to move my work and needed to place it on the server. Using VS 2005 , went to BUILD -Publish Web Site Checked the box for :: Alow this precompiled site to be updatable.
0
8392
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However, people are often confused as to whether an ONU can Work As a Router. In this blog post, we’ll explore What is ONU, What Is Router, ONU & Router’s main usage, and What is the difference between ONU and Router. Let’s take a closer look ! Part I. Meaning of...
0
8305
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can effortlessly switch the default language on Windows 10 without reinstalling. I'll walk you through it. First, let's disable language synchronization. With a Microsoft account, language settings sync across devices. To prevent any complications,...
0
8726
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven tapestry of website design and digital marketing. It's not merely about having a website; it's about crafting an immersive digital experience that captivates audiences and drives business growth. The Art of Business Website Design Your website is...
0
8603
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each protocol has its own unique characteristics and advantages, but as a user who is planning to build a smart home system, I am a bit confused by the choice of these technologies. I'm particularly interested in Zigbee because I've heard it does some...
0
7320
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing, and deployment—without human intervention. Imagine an AI that can take a project description, break it down, write the code, debug it, and then launch it, all on its own.... Now, this would greatly impact the work of software developers. The idea...
0
5632
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and then checking html paragraph one by one. At the time of converting from word file to html my equations which are in the word document file was convert into image. Globals.ThisAddIn.Application.ActiveDocument.Select();...
0
4151
by: TSSRALBI | last post by:
Hello I'm a network technician in training and I need your help. I am currently learning how to create and manage the different types of VPNs and I have a question about LAN-to-LAN VPNs. The last exercise I practiced was to create a LAN-to-LAN VPN between two Pfsense firewalls, by using IPSEC protocols. I succeeded, with both firewalls in the same network. But I'm wondering if it's possible to do the same thing, with 2 Pfsense firewalls...
0
4301
by: adsilva | last post by:
A Windows Forms form does not have the event Unload, like VB6. What one acts like?
1
2726
by: 6302768590 | last post by:
Hai team i want code for transfer the data from one system to another through IP address by using C# our system has to for every 5mins then we have to update the data what the data is updated we have to send another system

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.