Joomla and Session Fixation - Joomla! Forum - community, help and support


greetings,

i have joomla 2.5.7 installed , using multisites core extension. did pci scan on our sites, passed scan on our "master" site, go session fixation error on subordinated sites deployed using multisites. being able hijack session id.

i have contacted developer see if has solution. not sure if multisites, seem strange. checked other extensions cookies , sessions, did not see outside of core uses session ids.

here message getting qualys:

"the scanner found web application on target uses cookies. application seems use cookies (likely, session ids) in insecure way.
specifically, scanner created web session target using session id specified scanner itself. target application simply
started new session specified session id. issue called "session-fixation" , vulnerable session-hijacking attacks."

it seems have way session id being set. have experience how fix this?

thanks

is site hosted other company? or host on server? site running on add-on domains? or sub domains?





Comments

Popular posts from this blog

How to change text Component easybook reloaded *newbee* - Joomla! Forum - community, help and support

After Effect warning: A problem occurred when processing OpenGL commands

Preconditions Failed. - Joomla! Forum - community, help and support