473,503 Members | 1,760 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

Help needed ASAP, Security issue!

I have a security consultant group bashing Microsoft byt stating that the way
IIS handles Session ID is flawed. They're asking me to, once my users hit the
first asp page pre-authentication, to then destroy that session id
(ASPSESSIONID) and re-assign one. How can that be done? It's read only. And I
keep stating that this is in 128-bit SSL where the header is encrypted. Since
my code is coming from COM+ (VB6.0) and I'm recycling to the same 'asp' page,
I can not see a way to abandon the session, since I have items in the session
prior to login.
Is there a better approach?
Is there a way in COM+ VB to trick it by giving it a new page to reset the
session? I can abandon the session but I won't get a new ID since the page is
not re-rendered. And during that grey area I'm setting more session values.

I'm running on a Win2K server w/SP4 and the secureaspsessionid patch.

thanx!
Aug 18 '05 #1
0 975

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

8
5451
by: baustin75 | last post by:
Posted: Mon Oct 03, 2005 1:41 pm Post subject: cannot mail() in ie only when debugging in php designer 2005 -------------------------------------------------------------------------------- ...
8
1624
by: Anantha | last post by:
Hi All, We are haveing 4 DB's in our company, and presently we used to take offline backup on once in a week, we knew we cant recover last-in-time data. But we would like to shift to some new...
0
898
by: David | last post by:
I need to send e-mail from within an ASP.NET web page. Having problem. Need assistance Have two installation scenarios: 1) local machine (development machine connected to network); 2) network...
7
1233
by: Roshawn Dawson | last post by:
Hi, I have an xslt file located in the root directory. It is used by an aspx pages in both the root directory and a subdirectory. But for some strange reason, the aspx page in the subdirectory...
5
1600
by: Tiraman | last post by:
Hi , i have the A.dll in my GAC (only one occurrence) and after i deleted it from the GAC i saw that it still working . so i did IISRESET and now it throw an error . can we define the time...
5
1119
by: Brian Henry | last post by:
If i have a text box and want to input a text string into it then use my help files search to look for the inputted text from the application how would i do that? thanks
2
1430
by: lili | last post by:
I've had to take the site offline to work on it so I can see what's going on. Can anyone help? http://www.mauidesign.com/mauikaitest/index.html Two problems: 1. IE users (I think those on...
15
2551
by: Jay | last post by:
I have a multi threaded VB.NET application (4 threads) that I use to send text messages to many, many employees via system.timer at a 5 second interval. Basically, I look in a SQL table (queue) to...
4
2202
by: Brad Isaacs | last post by:
I am working with ASP.NET 2.0 and using an SQL Server 2000 database. I am using Visual Studio 2005 and developing on my Local machine. I am working with Login controls ASP.Configuration, I...
0
7199
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
0
7076
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can...
0
7323
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...
1
6984
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows...
0
7453
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...
0
4670
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and...
0
3162
by: TSSRALBI | last post by:
Hello I'm a network technician in training and I need your help. I am currently learning how to create and manage the different types of VPNs and I have a question about LAN-to-LAN VPNs. The...
0
1507
by: 6302768590 | last post by:
Hai team i want code for transfer the data from one system to another through IP address by using C# our system has to for every 5mins then we have to update the data what the data is updated ...
1
732
muto222
by: muto222 | last post by:
How can i add a mobile payment intergratation into php mysql website.

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.