This created session on RestartResponseAtInterceptPageException may also lead
to a possible "Session Fixation" attack in one that a malicious user tries
to access your site and is redirected to the login page but now with a
session created. The malicious user could then pass to a possible victim the
url to your site but also with the jsessionid of his session also in the
url. The victim user would then authenticate in your site and that session
would be marked as authenticaticated. But since the malicious user also
knows the jsessionid of the now authenticated session, he can also act as on
behalf of the user.

This is another reason why you would may want your LoginPage to be
stateless.

But to prevent such an attack reassigning a sessionid would solve this
attack.

-----
http://balamaci.wordpress.com 
--
View this message in context: 
http://apache-wicket.1842946.n4.nabble.com/Avoid-creating-an-HttpSession-before-login-tp4176286p4178605.html
Sent from the Users forum mailing list archive at Nabble.com.

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to