A Firefox extension that demonstrates HTTP session hijacking attacks.
firefox  wi-fi  extensão  plugin  sessão  session_highjacking  cookie  https  hacking  geek  security 
august 2012 by rtopitt
Sidejack Prevention - GitHub
GitHub was susceptible to this attack, but we have now taken measures to protect you and your data. The basic approach revolves around setting a second cookie (in addition to the normal session cookie) that is marked as secure. Cookies marked secure, are sent only over SSL requests and are omitted on non-SSL requests.
cookie  sessão  hijack  hack  geek  webapp  http  importante  inspiração  ssl  security 
october 2010 by rtopitt
Firesheep - Eric Butler - Software Developer in Seattle WA
HTTP session hijacking is when an attacker gets a hold of a user's cookie, allowing them to do anything the user can do on a particular website. On an open wireless network, cookies are basically shouted through the air, making these attacks extremely easy. Today at Toorcon 12 I announced the release of Firesheep, a Firefox extension designed to demonstrate just how serious this problem is.
cookie  firefox  https  http  webapp  hack  extensão  ssl  xsrf  sessão  importante  security 
october 2010 by rtopitt
self.works_with_ruby? - session_lifetime plugin
With session_lifetime you can set after how much time of inactivity your session should expire, you can execute an action when the session expires, and you can set where to redirect_to after session expiry.
expiração  inatividade  plugin  rails  sessão  security  tip 
may 2009 by rtopitt
SqlSessionStore now available as a plugin
Plugin para Rails que permite uma Session Store no banco de dados bem mais rápido.
mysql  performance  plugin  rails  sessão 
may 2009 by rtopitt
Roll your own SQL session store
Gravação de sessões em Rails no banco de dados via SQL direto, mais rápido
mysql  rails  sessão 
may 2009 by rtopitt
err.the_blog.find_by_title('Sessions N Such')
Visão geral sobre sessões em Ruby on Rails
artigo  blog  rails  sessão  tip 
may 2009 by rtopitt
Removing Stale Rails Sessions
Dica de script Ruby para rodar via cron para limpar a tabela de sessões de aplicações Rails periodicamente
cron  rails  script  sessão  shell  tip 
