Meaningful Tokens
Some session tokens are created using a transformation of the user’s user-
name or email address, or other information associated with them. This infor-
mation may be encoded or obfuscated in some way, and may be combined
with other data.
For example, the following token may initially appear to be a long random
string:
757365723d6461663b6170703d61646d696e3b646174653d30312f31322f3036
However, on closer inspection, it contains only hexadecimal characters.
Guessing that the string may actually be a hex-encoding of a string of ASCII
characters, we can run it through a decoder to reveal:
user=daf;app=admin;date=10/09/07
Do'stlaringiz bilan baham: |