Is ASP.NET membership protected from Firesheep?

My impression is that ASP.NET membership encrypts its cookie by default.

Can we assume that ASP.NET membership protects against session hijacking (ala Firesheep)?

+3
source share
3 answers

Membership in ASP.NET uses the same mechanism as any other site, and is absolutely vulnerable to a Firesheep attack. The cookie itself cannot be encrypted in such a way that it is not captured. All communication with the server must be encrypted to protect against session hijacking using SSL or WEP encryption.

+7
source

cookie , , .

+1

HTTPS.

Firesheep does not care about the contents of the cookie; all he needs to do is duplicate the cookie in the attacker's browser.

As long as the cookie is sent in clear text (unlike HTTPS or WPA), you are still vulnerable.

+1
source

Source: https://habr.com/ru/post/1774541/


All Articles