WebApp Sec mailing list archives

Re: Maia Mailgaurd http://www.renaissoft.com/maia/


From: Chuck <chuck.lists () gmail com>
Date: Mon, 18 Jul 2005 12:27:05 -0400

Oops, I meant to say that the application should invalidate session
IDs after some amount of time....  Sorry

Chuck

I also agree with you that the
application should not invalidate session IDs after some amount of
time to minimize the possibility of session hijacking.


Current thread: