25-Nov-2019 23:03

Most session fixation attacks are web based, and most rely on session identifiers being accepted from URLs (query string) or POST data.

There are several advantages of URL rewriting over above discussed approaches like it is browser independent and even if user’s browser does not support cookie or in case user has disabled cookies, this approach will work.For example we can create a cookie with name session Id with a unique value for each client and then can add it in a resposne so that it will be sent to client: The major disadvantage of cookies is browser provides a way to disable the cookies and in that case server will not be able to identify the user.