A Brief Analysis of ASP.NET Session Identifiers
by Timothy D. Morgan


(ASP).NET is a widely used web application development environment. In addition to many features considered standard for a web application platform, it provides built-in session management. Session identifiers are automatically generated and are typically provided to users (web browsers) as HTTP cookies. This paper provides a basic outline of how these session identifiers are generated which helps in better understanding their security.

Download: Full Article (128 kilobytes)

