Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-231

Information Disclosure in Session ID name

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Good To Have

      Description

      "Name of Session ID is 'ASP.NET Session ID' This reveals the
      development technology used "

      Please rename the Session ID cookie name

        Attachments

          Activity

          Hide
          vijayendra Vijayendra Shinde (Inactive) added a comment -

          Affected files: outer web.config

          Path: trunk\WORKTERRAweb\Web\Web Projects\Web.Config

          Added cookieName="WTCookie" attribute in SessionState.

          Show
          vijayendra Vijayendra Shinde (Inactive) added a comment - Affected files: outer web.config Path: trunk\WORKTERRAweb\Web\Web Projects\Web.Config Added cookieName="WTCookie" attribute in SessionState.
          Hide
          Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

          Confirmed that Session ID name is changed to WTCookie and does not reveal any technology related information.

          Show
          Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Confirmed that Session ID name is changed to WTCookie and does not reveal any technology related information.
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          Zeeshan Chishty no functional testing is involve in this ticket, if you are done with your testing kindly close.

          Show
          deepalit Deepali Tidke (Inactive) added a comment - Zeeshan Chishty no functional testing is involve in this ticket, if you are done with your testing kindly close.
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          Vijayendra Shinde here we are not sure which functionality exactly needs to be verified, please update accordingly as chnages are done into config file

          Show
          deepalit Deepali Tidke (Inactive) added a comment - Vijayendra Shinde here we are not sure which functionality exactly needs to be verified, please update accordingly as chnages are done into config file
          Hide
          vijayendra Vijayendra Shinde (Inactive) added a comment -

          Hi Deepali,

          Please follow below steps to test this-

          1. Login production with Chrome
          2. Press F12
          3. Refresh site page after login
          4. Go to Resources menu from window opened after F12
          5. Go to Cookies
          6. Search for WTCookie

          We have changed cookie name from ASP.NET_SessionId to WTCookie

          Let me know if you need more details on this.

          Show
          vijayendra Vijayendra Shinde (Inactive) added a comment - Hi Deepali, Please follow below steps to test this- 1. Login production with Chrome 2. Press F12 3. Refresh site page after login 4. Go to Resources menu from window opened after F12 5. Go to Cookies 6. Search for WTCookie We have changed cookie name from ASP.NET_SessionId to WTCookie Let me know if you need more details on this.
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          as per the above instructions , checked the cookie name on stage. cookie name can be seen as WTCookie

          Show
          deepalit Deepali Tidke (Inactive) added a comment - as per the above instructions , checked the cookie name on stage. cookie name can be seen as WTCookie
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          as per the above instructions , checked the cookie name on production. cookie name can be seen as WTCookie

          Show
          deepalit Deepali Tidke (Inactive) added a comment - as per the above instructions , checked the cookie name on production. cookie name can be seen as WTCookie

            People

            Assignee:
            deepalit Deepali Tidke (Inactive)
            Reporter:
            vijayendra Vijayendra Shinde (Inactive)
            Developer:
            Vijayendra Shinde (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Pre-Prod Due Date:
              Production Due Date: