Is keeping a login hash and password secure in a session?

What is the best way to save the SHA1 username and login for an intranet application?

Is a session a relatively secure way to store information such as multi-domain information, username and password? I save them asSession["data"] = customObject()

Does any additional step need to be taken to ensure the security of this data? Is there a potential security problem or hole that could be compromised? Some kind of injection session? Should I use some privatekey process to lock / open session data for reading?

+3
source share
2 answers

. , . (, ASP.net). , IMHO, , .

- , inProc, sqlserver, . .

, URL-, SHA1 . SHA256, .

, . - . , .

+4

, . InProc, , . SQL, , , - . - , .

0

Source: https://habr.com/ru/post/1789211/


All Articles