RequestRodeo: Client Side Protection against Session Riding
Martin Johns, Justus Winter · 2006
Abstract. The term Session Riding denotes a class of attacks on web applications that exploit implicit authentication processes. There are four distinct methods of implicit authentication found in today's web applica-tions: Cookies,