Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 3614586
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 18, 20262026-05-18T22:16:02+00:00 2026-05-18T22:16:02+00:00

I understand that it is possible to hijack the asp.net session by stealing the

  • 0

I understand that it is possible to hijack the asp.net session by stealing the asp.net session cookie. I guess that I’m thinking of stealing the cookie as it is transmitted over unsecure wi-fi.

Other than using SSL are there standard ways of securing this information? Or preventing the hijacking of the session?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-18T22:16:03+00:00Added an answer on May 18, 2026 at 10:16 pm

    Sadly, the only way to prevent cookies from being used in a replay attack is to send them over HTTPS since that ensures that the cookie itself is encrypted and, therefore, kept from prying eyes.

    Have you seen Jeff Atwood’s blog entry about this matter, Breaking the Web’s Cookie Jar? Jeff focuses more on the concerns from the user’s perspective, but it’s worth reading anyway. Here’s what he says folks can do today:

    So here’s what you can do to protect yourself, right now, today:

    1. We should be very careful how we browse on unencrypted wireless networks.

    2. Get in the habit of accessing your web mail through HTTPS.

    3. Lobby the websites you use to offer HTTPS browsing.

    This is very broad advice, and there are a whole host of technical caveats to the above. But it’s a starting point toward evangelizing the risks and responsible use of open wireless networks.

    There probably needs to be some sort of new, more secure approach for cookies going forward, but who knows if there will be enough traction to warrant such change or enough interest to spurn adoption. For web applications where security is paramount – think medical information websites, financial websites, and so on – the only plausible option is to require HTTS for the user’s entire browsing session.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

So, I understand that it's possible to set up in-app purchases for iPhone apps
I understand that it is not possible to tell what the user is doing
Is it possible to extract that info from the equivalence value? I understand that
I'm trying to understand if it's possible to create a set of variables that
I understand that wherever possible we shall use forward declarations instead of includes to
I understand that is not possible to have applications with multiple entry points under
I understand that it is possible to alter the PHP error reporting level site-wide,
I can't understand how is that possible, so i will just show the code.
I understand that it's possible (and I have done it) to return javascript and
I've read this question and I understand that its only possible to do it

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.