Find Jobs
Hire Freelancers

SSMC Project - Spring Security 3.2.8 + csrf + sessionFixation in AppScan

$30-250 USD

Cerrado
Publicado hace más de 2 años

$30-250 USD

Pagado a la entrega
I have a problem that the application is tested in appscan and show two error like. First, Session ID not updated - Insecure web application programming or configuration and Second, Cross-site request spoofing - Reject malicious requests. Cross-site request spoofing is solved with .csrf().disable() and the other (Second) not yet. Spring Security 3.2.8 + csrf + sessionFixation + WAS 8.5 + Ibm + Java + Primefaces + AppScan Session identifier not updated Severity: Medium CVSS Score: 6.4 URL: [login to view URL] Entity: [login to view URL] (Page) Risk: It is possible to steal or manipulate the client's session and cookies, which may be used to impersonate a legitimate user, allowing the hacker to view or alter the user records, and perform transactions as if you were that user Causes: Insecure web application programming or configuration Fix: Change session identifier values after login Reason: The test result seems to indicate a vulnerability because the identifiers of the session in the original Request (on the left) and in the response (on the right) are the same. They should have been updated in the answer. Cross-site request forgery Severity: Medium CVSS Score: 6.4 URL: [login to view URL] Entity: [login to view URL] (Page) Risk: It is possible to steal or manipulate the client's session and cookies, which may be used to impersonate a legitimate user, allowing the hacker to view or alter the user records, and perform transactions as if you were that user Causes: The authentication method used by the application is insufficient Fix: Reject malicious requests Reason: The test result seems to indicate the presence of a vulnerability, since the answer of the test (on the right) is identical to the original answer (on the left), indicating that Cross-Site Request Forgery attempt was successful, even though it includes a header Dummy 'referer'.
ID del proyecto: 31656746

Información sobre el proyecto

3 propuestas
Proyecto remoto
Activo hace 2 años

¿Buscas ganar dinero?

Beneficios de presentar ofertas en Freelancer

Fija tu plazo y presupuesto
Cobra por tu trabajo
Describe tu propuesta
Es gratis registrarse y presentar ofertas en los trabajos
3 freelancers están ofertando un promedio de $143 USD por este trabajo
Avatar del usuario
Hi, how are you? I go through the description and read it carefully, I know exactly what you are looking for. I have 5+ years’ experience in these skills Software Architecture, Java, J2EE, JavaScript and JSP. I have some question about this job, Please start chat, so we have detail discussion about your task. Thanks! Umair
$250 USD en 11 días
4,8 (6 comentarios)
3,2
3,2
Avatar del usuario
Greetings I can surely help you for SSMC Project - Spring Security 3.2.8 + csrf + sessionFixation in AppScan I am in the IT industry since more than a decade and serve so many clients for building and rebuilding websites, software and applications and I have strong hands-on different programming languages like PHP, CSS 3, Laravel, C++, C- Sharp, HTML, JAVA, .NET, Joomla, Click funnel, Angular, React, Node.js, Django etc., And I did migration from HTML to click funnels. I have made so many websites (E-commerce, WordPress, Classified admin, WooCommerce etc.), bots, softwares, Mobile application (Android, IOS and Huawei Play store) in my entire career. I have strong hands on both front end and backend. Currently I am part of the team who are dealing miscellaneous task in dubizzle and Mzad Qatar including design and layouts and they both have more than 1 million users. I believe that you are looking for a web designer and for sure you will get your end desire result with plagiarism free work and with better quality as I am assuring you this. Package deal can also be done for long term collaboration as per the client requirement. Kindly do come on chat for so that we can discuss project details further more.
$30 USD en 2 días
0,0 (1 comentario)
0,0
0,0

Sobre este cliente

Bandera de PERU
Lima, Peru
0,0
0
Miembro desde may 6, 2021

Verificación del cliente

Otros trabajos de este cliente

Torito App
$250-750 USD
¡Gracias! Te hemos enviado un enlace para reclamar tu crédito gratuito.
Algo salió mal al enviar tu correo electrónico. Por favor, intenta de nuevo.
Usuarios registrados Total de empleos publicados
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Cargando visualización previa
Permiso concedido para Geolocalización.
Tu sesión de acceso ha expirado y has sido desconectado. Por favor, inica sesión nuevamente.