Security issue in session id generation mechanism
Brought to you by:
drogatkin
Hi Dmitriy! Hi all!
I inspected code of TJWS and found security vulnerability in session id generation mechanism that lead to session hijacking attack. I sent all details to jAddressBook@gmail.com email as specified on http://tjws.sourceforge.net/ website.
Let me know if you have questions.
Anonymous
Build 106 made it less predictable