Find Jobs
Hire Freelancers

SSMC Project - Spring Security 3.2.8 + csrf + sessionFixation in AppScan

$30-250 USD

Closed
Posted over 2 years ago

$30-250 USD

Paid on delivery
I have a problem that the application is tested in appscan and show two error like. First, Session ID not updated - Insecure web application programming or configuration and Second, Cross-site request spoofing - Reject malicious requests. Cross-site request spoofing is solved with .csrf().disable() and the other (Second) not yet. Spring Security 3.2.8 + csrf + sessionFixation + WAS 8.5 + Ibm + Java + Primefaces + AppScan Session identifier not updated Severity: Medium CVSS Score: 6.4 URL: [login to view URL] Entity: [login to view URL] (Page) Risk: It is possible to steal or manipulate the client's session and cookies, which may be used to impersonate a legitimate user, allowing the hacker to view or alter the user records, and perform transactions as if you were that user Causes: Insecure web application programming or configuration Fix: Change session identifier values after login Reason: The test result seems to indicate a vulnerability because the identifiers of the session in the original Request (on the left) and in the response (on the right) are the same. They should have been updated in the answer. Cross-site request forgery Severity: Medium CVSS Score: 6.4 URL: [login to view URL] Entity: [login to view URL] (Page) Risk: It is possible to steal or manipulate the client's session and cookies, which may be used to impersonate a legitimate user, allowing the hacker to view or alter the user records, and perform transactions as if you were that user Causes: The authentication method used by the application is insufficient Fix: Reject malicious requests Reason: The test result seems to indicate the presence of a vulnerability, since the answer of the test (on the right) is identical to the original answer (on the left), indicating that Cross-Site Request Forgery attempt was successful, even though it includes a header Dummy 'referer'.
Project ID: 31656746

About the project

3 proposals
Remote project
Active 3 yrs ago

Looking to make some money?

Benefits of bidding on Freelancer

Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
3 freelancers are bidding on average $143 USD for this job
User Avatar
Hi, how are you? I go through the description and read it carefully, I know exactly what you are looking for. I have 5+ years’ experience in these skills Software Architecture, Java, J2EE, JavaScript and JSP. I have some question about this job, Please start chat, so we have detail discussion about your task. Thanks! Umair
$250 USD in 11 days
4.8 (6 reviews)
3.2
3.2
User Avatar
Greetings I can surely help you for SSMC Project - Spring Security 3.2.8 + csrf + sessionFixation in AppScan I am in the IT industry since more than a decade and serve so many clients for building and rebuilding websites, software and applications and I have strong hands-on different programming languages like PHP, CSS 3, Laravel, C++, C- Sharp, HTML, JAVA, .NET, Joomla, Click funnel, Angular, React, Node.js, Django etc., And I did migration from HTML to click funnels. I have made so many websites (E-commerce, WordPress, Classified admin, WooCommerce etc.), bots, softwares, Mobile application (Android, IOS and Huawei Play store) in my entire career. I have strong hands on both front end and backend. Currently I am part of the team who are dealing miscellaneous task in dubizzle and Mzad Qatar including design and layouts and they both have more than 1 million users. I believe that you are looking for a web designer and for sure you will get your end desire result with plagiarism free work and with better quality as I am assuring you this. Package deal can also be done for long term collaboration as per the client requirement. Kindly do come on chat for so that we can discuss project details further more.
$30 USD in 2 days
0.0 (1 review)
0.0
0.0

About the client

Flag of PERU
Lima, Peru
0.0
0
Member since May 6, 2021

Client Verification

Other jobs from this client

Torito App
$250-750 USD
Thanks! We’ve emailed you a link to claim your free credit.
Something went wrong while sending your email. Please try again.
Registered Users Total Jobs Posted
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Loading preview
Permission granted for Geolocation.
Your login session has expired and you have been logged out. Please log in again.