Find Jobs
Hire Freelancers

SSMC Project - Spring Security 3.2.8 + csrf + sessionFixation in AppScan

$30-250 USD

Închis
Data postării: peste 2 ani în urmă

$30-250 USD

Plata la predare
I have a problem that the application is tested in appscan and show two error like. First, Session ID not updated - Insecure web application programming or configuration and Second, Cross-site request spoofing - Reject malicious requests. Cross-site request spoofing is solved with .csrf().disable() and the other (Second) not yet. Spring Security 3.2.8 + csrf + sessionFixation + WAS 8.5 + Ibm + Java + Primefaces + AppScan Session identifier not updated Severity: Medium CVSS Score: 6.4 URL: [login to view URL] Entity: [login to view URL] (Page) Risk: It is possible to steal or manipulate the client's session and cookies, which may be used to impersonate a legitimate user, allowing the hacker to view or alter the user records, and perform transactions as if you were that user Causes: Insecure web application programming or configuration Fix: Change session identifier values after login Reason: The test result seems to indicate a vulnerability because the identifiers of the session in the original Request (on the left) and in the response (on the right) are the same. They should have been updated in the answer. Cross-site request forgery Severity: Medium CVSS Score: 6.4 URL: [login to view URL] Entity: [login to view URL] (Page) Risk: It is possible to steal or manipulate the client's session and cookies, which may be used to impersonate a legitimate user, allowing the hacker to view or alter the user records, and perform transactions as if you were that user Causes: The authentication method used by the application is insufficient Fix: Reject malicious requests Reason: The test result seems to indicate the presence of a vulnerability, since the answer of the test (on the right) is identical to the original answer (on the left), indicating that Cross-Site Request Forgery attempt was successful, even though it includes a header Dummy 'referer'.
ID-ul proiectului: 31656746

Despre proiect

3 propuneri
Proiect la distanță
Activ: 2 ani în urmă

Vrei să câștigi bani?

Avantajele de a licita pe platforma Freelancer

Stabilește bugetul și intervalul temporal
Îți primești plata pentru serviciile prestate
Evidențiază-ți propunerea
Te înregistrezi și licitezi gratuit pentru proiecte
3 freelanceri plasează o ofertă medie de $143 USD pentru proiect
Avatarul utilizatorului
Hi, how are you? I go through the description and read it carefully, I know exactly what you are looking for. I have 5+ years’ experience in these skills Software Architecture, Java, J2EE, JavaScript and JSP. I have some question about this job, Please start chat, so we have detail discussion about your task. Thanks! Umair
$250 USD în 11 zile
4,8 (6 recenzii)
3,2
3,2
Avatarul utilizatorului
Greetings I can surely help you for SSMC Project - Spring Security 3.2.8 + csrf + sessionFixation in AppScan I am in the IT industry since more than a decade and serve so many clients for building and rebuilding websites, software and applications and I have strong hands-on different programming languages like PHP, CSS 3, Laravel, C++, C- Sharp, HTML, JAVA, .NET, Joomla, Click funnel, Angular, React, Node.js, Django etc., And I did migration from HTML to click funnels. I have made so many websites (E-commerce, WordPress, Classified admin, WooCommerce etc.), bots, softwares, Mobile application (Android, IOS and Huawei Play store) in my entire career. I have strong hands on both front end and backend. Currently I am part of the team who are dealing miscellaneous task in dubizzle and Mzad Qatar including design and layouts and they both have more than 1 million users. I believe that you are looking for a web designer and for sure you will get your end desire result with plagiarism free work and with better quality as I am assuring you this. Package deal can also be done for long term collaboration as per the client requirement. Kindly do come on chat for so that we can discuss project details further more.
$30 USD în 2 zile
0,0 (1 recenzie)
0,0
0,0

Despre client

Steagul PERU
Lima, Peru
0,0
0
Membru din mai 6, 2021

Verificarea clientului

Alte proiecte ale acestui client

Torito App
$250-750 USD
Mulțumim! Ți-am trimis prin e-mail linkul pe care trebuie să-l accesezi pentru a revendica creditul gratuit.
A apărut o eroare la trimiterea e-mailului. Încearcă din nou.
Utilizatori înregistrați Totalul proiectelor postate
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Se încarcă previzualizarea
S-a oferit permisiunea de depistare a locației.
Ți-a expirat sesiunea pentru conectare sau te-ai deconectat. Conectează-te din nou.