WebApp Sec mailing list archives

Re: Session Management and IP address - experiences?


From: Saqib.N.Ali () seagate com
Date: Thu, 2 Sep 2004 21:56:00 -0700

As such, we have been recommending against this practice for many years
unless it is done in a controlled (i.e., intranet) environment where 
none of
the users exhibit this type of behavior.

If it is a intranet environment, wouldn't it better to do client 
authentication using certificate, and thus preventing the attacker from 
hijacking the session? 

IP addresses can be spoofed and if both the attacker and legit user are 
behind the same NAT, session management using IP defeats the purpose.

In Peace,
Saqib Ali
http://validate.sf.net


Current thread: