@Eric Well the attack vector remains if adding a fake cookie trigger the extra session creation.
And the one hour timeout proposed seems to big according to comment #13 assumption where only 1/2 hours is required to overwhelm the service...
How about the monkey patch of SessionStore.load method, wouldn't it be easer to implement ?
@Eric Well the attack vector remains if adding a fake cookie trigger the extra session creation.
And the one hour timeout proposed seems to big according to comment #13 assumption where only 1/2 hours is required to overwhelm the service...
How about the monkey patch of SessionStore.load method, wouldn't it be easer to implement ?