c# - invalidate aspx authentification cookie -
i have asp.net web form. when user authenticate, create secured cookie called .aspxauth
uppon logout, call these 2 methods
formsauthentication.signout(); session.abandon() problem had penetration test , if steal cookie, logout , manually reinsert cookie, become loggued in again. .aspauth isn't invalidated server side.
i've googled , can't find answer security breach.
read article session fixation , how rid of once , all:
Comments
Post a Comment