Find Jobs
Hire Freelancers

SSMC Project - Spring Security 3.2.8 + csrf + sessionFixation in AppScan

$30-250 USD

Fechado
Publicado há mais de 2 anos

$30-250 USD

Pago na entrega
I have a problem that the application is tested in appscan and show two error like. First, Session ID not updated - Insecure web application programming or configuration and Second, Cross-site request spoofing - Reject malicious requests. Cross-site request spoofing is solved with .csrf().disable() and the other (Second) not yet. Spring Security 3.2.8 + csrf + sessionFixation + WAS 8.5 + Ibm + Java + Primefaces + AppScan Session identifier not updated Severity: Medium CVSS Score: 6.4 URL: [login to view URL] Entity: [login to view URL] (Page) Risk: It is possible to steal or manipulate the client's session and cookies, which may be used to impersonate a legitimate user, allowing the hacker to view or alter the user records, and perform transactions as if you were that user Causes: Insecure web application programming or configuration Fix: Change session identifier values after login Reason: The test result seems to indicate a vulnerability because the identifiers of the session in the original Request (on the left) and in the response (on the right) are the same. They should have been updated in the answer. Cross-site request forgery Severity: Medium CVSS Score: 6.4 URL: [login to view URL] Entity: [login to view URL] (Page) Risk: It is possible to steal or manipulate the client's session and cookies, which may be used to impersonate a legitimate user, allowing the hacker to view or alter the user records, and perform transactions as if you were that user Causes: The authentication method used by the application is insufficient Fix: Reject malicious requests Reason: The test result seems to indicate the presence of a vulnerability, since the answer of the test (on the right) is identical to the original answer (on the left), indicating that Cross-Site Request Forgery attempt was successful, even though it includes a header Dummy 'referer'.
ID do Projeto: 31656746

Sobre o projeto

3 propostas
Projeto remoto
Ativo há 2 anos

Quer ganhar algum dinheiro?

Benefícios de ofertar no Freelancer

Defina seu orçamento e seu prazo
Seja pago pelo seu trabalho
Descreva sua proposta
É grátis para se inscrever e fazer ofertas em trabalhos
3 freelancers estão ofertando em média $143 USD for esse trabalho
Avatar do Usuário
Hi, how are you? I go through the description and read it carefully, I know exactly what you are looking for. I have 5+ years’ experience in these skills Software Architecture, Java, J2EE, JavaScript and JSP. I have some question about this job, Please start chat, so we have detail discussion about your task. Thanks! Umair
$250 USD em 11 dias
4,8 (6 avaliações)
3,2
3,2
Avatar do Usuário
Greetings I can surely help you for SSMC Project - Spring Security 3.2.8 + csrf + sessionFixation in AppScan I am in the IT industry since more than a decade and serve so many clients for building and rebuilding websites, software and applications and I have strong hands-on different programming languages like PHP, CSS 3, Laravel, C++, C- Sharp, HTML, JAVA, .NET, Joomla, Click funnel, Angular, React, Node.js, Django etc., And I did migration from HTML to click funnels. I have made so many websites (E-commerce, WordPress, Classified admin, WooCommerce etc.), bots, softwares, Mobile application (Android, IOS and Huawei Play store) in my entire career. I have strong hands on both front end and backend. Currently I am part of the team who are dealing miscellaneous task in dubizzle and Mzad Qatar including design and layouts and they both have more than 1 million users. I believe that you are looking for a web designer and for sure you will get your end desire result with plagiarism free work and with better quality as I am assuring you this. Package deal can also be done for long term collaboration as per the client requirement. Kindly do come on chat for so that we can discuss project details further more.
$30 USD em 2 dias
0,0 (1 avaliação)
0,0
0,0

Sobre o cliente

Bandeira do(a) PERU
Lima, Peru
0,0
0
Membro desde mai. 6, 2021

Verificação do Cliente

Outros trabalhos deste cliente

Torito App
$250-750 USD
Obrigado! Te enviamos um link por e-mail para que você possa reivindicar seu crédito gratuito.
Algo deu errado ao enviar seu e-mail. Por favor, tente novamente.
Usuários Registrados Total de Trabalhos Publicados
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Carregando pré-visualização
Permissão concedida para Geolocalização.
Sua sessão expirou e você foi desconectado. Por favor, faça login novamente.