OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: James Fleming (jamesfleming94588yahoo.com)
Date: Mon Jun 17 2002 - 22:25:55 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    I have an existing Java based application running on
    Tomat after reading iDefense's session ID paper tand
    the great work at OWASP I looked at the app and found
    the session ID was only 8 chars long.

    Given thats controlled by the app server and not the
    application code does anyone know how I can specify
    the amount of entropy in the session ID in Tomcat, BEA
    and WebSphere ?

    __________________________________________________
    Do You Yahoo!?
    Yahoo! - Official partner of 2002 FIFA World Cup
    http://fifaworldcup.yahoo.com