Session is not destructed after logout

To check if an application correctly closes the session, open the application using Burp Suite and then log in to the application with valid credentials:

  1. As you can see from the following screenshot, the application created a session that is used as a guest user:
  1. Now, access the application, and you will see that the application now creates a new session as a logged user.
  2. Close the session, as follows:
  1. If the application correctly destroyed the session, it is not possible to resend a request. Go to History, and select a request made by the user.
  2. Click on Send to repeated and click on Go, and see the result. If the application returns the response as a logged user, the application is vulnerable; if not, the application is not vulnerable.
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.191.46.36