Joomla and Session Fixation - Joomla! Forum - community, help and support
greetings,
i have joomla 2.5.7 installed , using multisites core extension. did pci scan on our sites, passed scan on our "master" site, go session fixation error on subordinated sites deployed using multisites. being able hijack session id.
i have contacted developer see if has solution. not sure if multisites, seem strange. checked other extensions cookies , sessions, did not see outside of core uses session ids.
here message getting qualys:
"the scanner found web application on target uses cookies. application seems use cookies (likely, session ids) in insecure way.
specifically, scanner created web session target using session id specified scanner itself. target application simply
started new session specified session id. issue called "session-fixation" , vulnerable session-hijacking attacks."
it seems have way session id being set. have experience how fix this?
thanks
i have joomla 2.5.7 installed , using multisites core extension. did pci scan on our sites, passed scan on our "master" site, go session fixation error on subordinated sites deployed using multisites. being able hijack session id.
i have contacted developer see if has solution. not sure if multisites, seem strange. checked other extensions cookies , sessions, did not see outside of core uses session ids.
here message getting qualys:
"the scanner found web application on target uses cookies. application seems use cookies (likely, session ids) in insecure way.
specifically, scanner created web session target using session id specified scanner itself. target application simply
started new session specified session id. issue called "session-fixation" , vulnerable session-hijacking attacks."
it seems have way session id being set. have experience how fix this?
thanks
is site hosted other company? or host on server? site running on add-on domains? or sub domains?
Comments
Post a Comment