OWASP / wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
https://owasp.org/www-project-web-security-testing-guide/
Creative Commons Attribution Share Alike 4.0 International
7.35k stars 1.33k forks source link

Update Privilege Escalation's Weak SessionID Section #1130

Closed ThunderSon closed 1 month ago

ThunderSon commented 9 months ago

What's the issue? Privilege Escalation guide contains a section at the end called Weak SessionID that feels a bit out of place and could take a rewrite

How do we solve it? See if the section is still required, if it can be merged into other sections, or if it simply needs a better rewrite to belong to the rest of the content

Would you like to be assigned to this issue? Check the box if you will submit a PR to fix this issue. Please read CONTRIBUTING.md.

Lucas-Schmucas commented 1 month ago

I would be happy to help. Could you assign me, please? I can't add a check to the little box, unfortunately :(

Lucas-Schmucas commented 1 month ago

I think the section “Weak SessionID” is already described in great detail in WSTG-SESS-01 - Session Analysis. It is therefore not necessary to move it, which is why I have removed it.