Groups > Weblogic > WebLogic security > Session stealing




Session stealing

Session stealing
Wed, 23 Apr 2008 05:44:10 -070
How can i avoid session stealing?

I am accessing a portal application. When i enter the application after
successful authentication, if i copy the current URL and paste into new browser,
the protected page has been displayed without challenging for User
credentials!!

How can i avoid it?

Scenario:
Portal Application deployed on WebLogic 9.2 sp2 portal server.
Post Reply
about | contact