Golgappa.net | Golgappa.org | BagIndia.net | BodyIndia.Com | CabIndia.net | CarsBikes.net | CarsBikes.org | CashIndia.net | ConsumerIndia.net | CookingIndia.net | DataIndia.net | DealIndia.net | EmailIndia.net | FirstTablet.com | FirstTourist.com | ForsaleIndia.net | IndiaBody.Com | IndiaCab.net | IndiaCash.net | IndiaModel.net | KidForum.net | OfficeIndia.net | PaysIndia.com | RestaurantIndia.net | RestaurantsIndia.net | SaleForum.net | SellForum.net | SoldIndia.com | StarIndia.net | TomatoCab.com | TomatoCabs.com | TownIndia.com
Interested to Buy Any Domain ? << Click Here >> for more details...

Do ASP.NET forms authentication cookies provide any protection against replay attacks? Do they, for example, include the client's IP address or anything else that would distinguish the real client from an attacker?

Answer Posted / surendra singh

No. If an authentication cookie is stolen, it can be used by an attacker. It's up to you to prevent this from happening by using an encrypted communications channel (HTTPS). Authentication cookies issued as session cookies, do, however,include a time-out valid that limits their lifetime. So a stolen session cookie can only be used in replay attacks as long as the ticket inside the cookie is valid. The default time-out interval is 30 minutes.You can change that by modifying the timeout attribute accompanying the <forms> element in Machine.config or a local Web.config file. Persistent authentication cookies do not time-out and therefore are a more serious security threat if stolen.

Is This Answer Correct ?    0 Yes 0 No



Post New Answer       View All Answers


Please Help Members By Posting Answers For Below Questions

Why should i prefer JSP over asp.net or any other web development language..??

1997


What is the difference between the response.write() and response.output.write() methods?

1011


What is the extension of master page in asp.net?

978


What is the difference between “Web.config” and “Machine.Config”?

1139


Is it possible to write code in many languages in one asp.net project?

1032


To wrap up a call to a Web service the standard used is..?

980


What should you do is you want to remove an existing component but would like to make some funtionalities?

1941


What is a SESSION and APPLICATION object?

1037


Explain why datareader is useful?

997


What is difference between or and orelse?

994


Explain what is an assembly?

972


Explain parts of assembly?

970


How can we create a website?

950


Which is the parent class of the web server control?

1070


What is master page in dtp?

988