Hold Your Sessions: An Attack on Java Session-Id Generation

Zvi Gutterman, Dahlia Malkhi. Hold Your Sessions: An Attack on Java Session-Id Generation. In Alfred Menezes, editor, Topics in Cryptology - CT-RSA 2005, The Cryptographers Track at the RSA Conference 2005, San Francisco, CA, USA, February 14-18, 2005, Proceedings. Volume 3376 of Lecture Notes in Computer Science, pages 44-57, Springer, 2005. [doi]

@inproceedings{GuttermanM05,
  title = {Hold Your Sessions: An Attack on Java Session-Id Generation},
  author = {Zvi Gutterman and Dahlia Malkhi},
  year = {2005},
  url = {http://springerlink.metapress.com/openurl.asp?genre=article&issn=0302-9743&volume=3376&spage=44},
  tags = {Java},
  researchr = {https://researchr.org/publication/GuttermanM05},
  cites = {0},
  citedby = {0},
  pages = {44-57},
  booktitle = {Topics in Cryptology - CT-RSA 2005, The Cryptographers  Track at the RSA Conference 2005, San Francisco, CA, USA, February 14-18, 2005, Proceedings},
  editor = {Alfred Menezes},
  volume = {3376},
  series = {Lecture Notes in Computer Science},
  publisher = {Springer},
  isbn = {3-540-24399-2},
}