<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><category>pcsoft.us.windev</category><copyright>Copyright 2026, PC SOFT</copyright><lastBuildDate>15 May 2017 14:05:00 Z</lastBuildDate><pubDate>11 May 2017 15:12:00 Z</pubDate><description>After one scan of one webdev application we encounter the following problem:&#13;
If we copy the URL of one dynamic page send it by emails to another PC and use it the other user can see the data.&#13;
&#13;
Anyone manage to solve this issue in the dynamic webdev sites?&#13;
&#13;
Result of the scan:&#13;
Sensitive information within URLs may be logged in various locations, including the user's browser,&#13;
the web server, and any forward or reverse proxy or caching servers between the two endpoints.&#13;
URLs may also be displayed on-screen, bookmarked or emailed between users. This can also allow for&#13;
the disclosure of the session token to a third party via the Referrer header when any off-site links are&#13;
followed.&#13;
Placing session tokens into the URL increases the risk that they will be captured by an attacker. A&#13;
compromise would allow an attacker unauthenticated access to a valid user's session, placing the&#13;
application user's personal information at risk as well as increasing the likelihood of loss of integrity&#13;
and confidentiality within the application.&#13;
Session tokens hardcoded into the HTML for access to other locations can enable an attacker to&#13;
impersonate the application regardless of the user and gain access to application functionality or&#13;
information that usually requires a license.</description><ttl>30</ttl><generator>WEBDEV</generator><language>en_US</language><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp</link><title>[WB] - Dynamic webdev site and session Hijacking</title><managingEditor>moderateur@pcsoft.fr (El moderador)</managingEditor><webMaster>webmaster@pcsoft.fr (El webmaster)</webMaster><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60877/read.awp</comments><pubDate>15 May 2017 14:05:00 Z</pubDate><description>Hi Mr. Black,&#13;
&#13;
The exact scenario (as stated above) is excellently described here.&#13;
Quote&#13;
Microsoft asp.net&#13;
&#13;
Cross-site req…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60877/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60877/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp">[WB] - Dynamic webdev site and session Hijacking</source><title>Re: [WB] - Dynamic webdev site and session Hijacking</title></item><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60875/read.awp</comments><pubDate>15 May 2017 12:36:00 Z</pubDate><description>hi Paulo,&#13;
&#13;
I'm confused also. I thought a dynamic page with automatic session management option (AWP unchecked) placed the ses…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60875/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60875/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp">[WB] - Dynamic webdev site and session Hijacking</source><title>Re: [WB] - Dynamic webdev site and session Hijacking</title></item><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60873/read.awp</comments><pubDate>15 May 2017 11:06:00 Z</pubDate><description>Hi Paolo,&#13;
&#13;
You could also use NetMachineName() to identify the workstation.&#13;
&#13;
Kind regards,&#13;
Piet</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60873/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60873/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp">[WB] - Dynamic webdev site and session Hijacking</source><title>Re: [WB] - Dynamic webdev site and session Hijacking</title></item><item><author>pvsoftware</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60845/read.awp</comments><pubDate>12 May 2017 13:14:12 Z</pubDate><description>I have a login page, when closing this page I use the contextclose resource, in my case this problem does not occur that you are…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60845/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60845/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp">[WB] - Dynamic webdev site and session Hijacking</source><title>Re: [WB] - Dynamic webdev site and session Hijacking</title></item><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60834/read.awp</comments><pubDate>11 May 2017 19:29:00 Z</pubDate><description>One possible solution I'm thinking about would be:&#13;
1. Store the value of CurrentPage in one global variable in the first page o…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60834/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60834/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp">[WB] - Dynamic webdev site and session Hijacking</source><title>Re: [WB] - Dynamic webdev site and session Hijacking</title></item><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60833/read.awp</comments><pubDate>11 May 2017 16:53:00 Z</pubDate><description>Fabrice,&#13;
&#13;
I'm using the method you describe in point 1 but the app scan still reports the error.&#13;
I can't use method 2 because…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60833/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60833/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp">[WB] - Dynamic webdev site and session Hijacking</source><title>Re: [WB] - Dynamic webdev site and session Hijacking</title></item><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60832/read.awp</comments><pubDate>11 May 2017 16:27:00 Z</pubDate><description>Hi Paulo,&#13;
&#13;
To give you an idea, you can read all about security and anti-forgery (session hijacking) and how it is implemented…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60832/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60832/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp">[WB] - Dynamic webdev site and session Hijacking</source><title>Re: [WB] - Dynamic webdev site and session Hijacking</title></item><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60831/read.awp</comments><pubDate>11 May 2017 16:24:00 Z</pubDate><description>Hi Paulo,&#13;
&#13;
there are several solutions to solve this problem... They all bog down to identifying the COMPUTER using the sessio…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60831/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60831/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp">[WB] - Dynamic webdev site and session Hijacking</source><title>Re: [WB] - Dynamic webdev site and session Hijacking</title></item><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60828/read.awp</comments><pubDate>11 May 2017 15:56:00 Z</pubDate><description>Hi Piet,&#13;
&#13;
Using the same app installed in the same server and tested with several clients sometimes i get the same result as y…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60828/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60828/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp">[WB] - Dynamic webdev site and session Hijacking</source><title>Re: [WB] - Dynamic webdev site and session Hijacking</title></item><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60830/read.awp</comments><pubDate>11 May 2017 15:33:00 Z</pubDate><description>Hi Paolo,&#13;
&#13;
If I copy and paste an url, I always get "The session does not exist anymore".&#13;
&#13;
Kind regards,&#13;
Piet</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60830/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking-60830/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/60827-dynamic-webdev-site-and-session-hijacking/read.awp">[WB] - Dynamic webdev site and session Hijacking</source><title>Re: [WB] - Dynamic webdev site and session Hijacking</title></item></channel></rss>
