Identifying Weak Session Tokens Using Entropy - Tradecraft Security Weekly #15

Share:

Listens: 0

Tradecraft Security Weekly (Video)

Technology


Session management in web applications is extremely important in regards to securing user credentials and integrity within the application. Sometimes session tokens can be predicted provided the overall randomness is weak. If this is possible a remote attacker may be able to compromise the session of an authenticated user. In this episode of Tradecraft Security Weekly both Beau Bullock (@dafthack) and Mike Felch (@ustayready) discuss the issues associated with creating session tokens with weak entropy.