Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: Is logoff feature necessary

Re: Is logoff feature necessary

From: Luciano Miguel Ferreira Rocha <strange_at_nsk.no-ip.org>
Date: Tue, 2 May 2006 10:32:20 +0100

On Tue, May 02, 2006 at 07:41:02AM -0000, test.future_at_gmail.com wrote:
> We have a web applicaiton which do not have logoff button. The developer claims that it is unnecessary, since the session can be terminated by closing the browser. Is it correct? Thanks.

Yes, session cookies are removed on exit. But why force people to
terminate the browser when they want to logout from that site?

-- 
lfr
0/0

  • application/pgp-signature attachment: stored
Received on May 03 2006
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos