This created session on RestartResponseAtInterceptPageException may also lead to a possible "Session Fixation" attack in one that a malicious user tries to access your site and is redirected to the login page but now with a session created. The malicious user could then pass to a possible victim the url to your site but also with the jsessionid of his session also in the url. The victim user would then authenticate in your site and that session would be marked as authenticaticated. But since the malicious user also knows the jsessionid of the now authenticated session, he can also act as on behalf of the user.
This is another reason why you would may want your LoginPage to be stateless. But to prevent such an attack reassigning a sessionid would solve this attack. ----- http://balamaci.wordpress.com -- View this message in context: http://apache-wicket.1842946.n4.nabble.com/Avoid-creating-an-HttpSession-before-login-tp4176286p4178605.html Sent from the Users forum mailing list archive at Nabble.com. --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
