A session is a period of time linked to a user, which is initiated when he/she arrives at a web application and it ends when his/her browser is closed or after a certain time of inactivity. Attackers can hijack a user's session by exploiting session management vulnerabilities by means of session fixation and cross-site request forgery attacks.
Very often, session IDs are not only identification tokens, but also authenticators. This means that upon login, users are authenticated based on their credentials (e.g., usernames/passwords or digital certificates) and issued session IDs that will effectively serve as temporary static passwords for accessing their sessions. This makes session IDs a very appealing target for attackers. In many cases, an attacker who manages to obtain a valid ID of user’s session can use it to directly enter that session – often without arising user’s suspicion. A secure session management must be implemented in the development phase of web applications because it is the responsibility of the web application, and not the underlying web server.
Threat modeling is a systematic process that is used to identify threats and vulnerabilities in software and has become popular technique to help system designers think about the security threats that their system might face.
In this paper we design the threat modeling for session’s ID threat by using SeaMonster security modeling software, and then propose a secure session management that avoids the vulnerabilities. The proposed secure session management is designed to give trust authentication between the client and the server to avoid session hijacing attack by using both: server session’s ID and MAC address of the client.Visual Studio. Net 2008 is used in implementing the proposed system
This research is concerned with studying (the concept of freedom in the texts of Yaşar Kamal the play), as the Turkish playwright (Kamal Yasar) is one of the contemporary playwrights who have been interested in and criticize society, and perhaps the concept of freedom in his texts took a different form, through his ability to renew and present his attempts to create A theatrical form different from his earlier writers in dealing with the life of the peasants and the oppression that went through them, as the researcher identified the problem of his research with the following question: What is the concept of freedom in the texts of Yashar Kamal? The research aims to define the concept of freedom in the texts of Yashar Kamal of the play,
... Show MoreAt the beginning of the nineties increased responsibility of the auditor to the community as the demand for auditing the environmental performance for the economic units in addition to audit the financial performance. With the aim of preserving the environment and reducing the damagse as aresult of the negative effects of the activities of these units.
The researh deal with two sides the first one identifies the theoretical framework of the concept of environmental audits, requirements, methods, types of procedures, and duties of the auditor in conducting environmental audits. It also deals with the concept of the enviro
... Show MoreAttempts were made over the years to achieve economic and easy methods for water purification. This could well save time, cost, and earn a good process quality for many countries. This study aims to enhance the purification process parameters for Congo red dye polluted water and introduce a developed methodology with an impact on many associated parameters such as the time for water purification process. The research proposes a method to achieve this time reduction by mixing gold nanoparticle (AuNPs) (prepared by chemical reduction method) with Titanium dioxide nanoparticles (TiO2NPs) (prepared by sol-gel techniques). The resulting mixture is incorporated into PVA host to synthesize a hard disk used as a purification d
... Show MoreTesting the sensitivity of periodontal pathogens requires the selection of an easier and more reliable method to be used with such anaerobic bacteria that need a long period of time for growth. Natural materials are a new era of antibacterial agents to control periodontal infections. The aims of the current study were to test the antibacterial activity of two natural agents, namely olibanum and alum, against three types of red complex periodontal pathogens and compare the application of agar diffusion and microdilution methods for testing the susceptibility. Gingival crevicular fluid from pockets with chronic infections was sampled as a source for the three types of bacteria, Porphyromonas gingivalis, Tannerella forsythia
... Show MoreA series of Schiff base-bearing salicylaldehyde moiety compounds (1-4) had been designed, synthesized, subjected to insilico ADMET prediction, molecular docking, characterization by FT-IR, and CHNS analysis techniques, and finally to their Anti-inflammatory profile using cyclooxygenase fluorescence inhibitor screening assay methods along with standard drugs, celecoxib, and diclofenac. The ADMET studies were used to predict which compounds would be suitable for oral administration, as well as absorption sites, bioavailability, TPSA, and drug likeness. According to the results of ADME data, all of the produced chemicals can be absorbed through the GIT and have passed Lipinski’s rule of five. Through molecular docking with PyRx 0.8, these
... Show MoreThe behavior investigation of castellated beams with fiber-reinforced lightweight concrete deck slab as a modified choice for composite steel-concrete beams affected by harmonic load is presented in this study. The experimental program involved six fixed-supported castellated beams of 2140mm size. Three types of concrete were included: Normal Weight Concrete (NWC), Lightweight Aggregate Concrete (LWAC), and Lightweight Fiber-Reinforced Aggregate Concrete (LWACF). The specimens were divided into two groups: the first comprised three specimens tested under harmonic load effect of 30Hz operation frequency for 3 days, then the residual strength was determined through static load application. The second group included three specimens ide
... Show MoreIn this study, a traumatic spinal cord injury (TSCI) classification system is proposed using a convolutional neural network (CNN) technique with automatically learned features from electromyography (EMG) signals for a non-human primate (NHP) model. A comparison between the proposed classification system and a classical classification method (k-nearest neighbors, kNN) is also presented. Developing such an NHP model with a suitable assessment tool (i.e., classifier) is a crucial step in detecting the effect of TSCI using EMG, which is expected to be essential in the evaluation of the efficacy of new TSCI treatments. Intramuscular EMG data were collected from an agonist/antagonist tail muscle pair for the pre- and post-spinal cord lesi
... Show MoreBackground: Langerhans' cell histiocytosis (LCH) is a group of conditions affecting the reticuloendothelial system. It includes Letterer-Siwe disease, Hand-Schuller-Christian disease and eosinophilic granuloma and most often presents in childhood. Materials and methods: Twenty-five cases of LCH were diagnosed histologically and confirmed by CD1a antibody and assessed immunohistochemically using anti-RANKL and anti-RANK antibodies to evaluate osteoclastogenic mechanism. Results: Regarding jaw cases, there was a significant correlation between CD1a and RANK (P=0.016). While in the skull, highly significant correlation existed between RANK and RANKL (p=0.001). Among the sites, there was no statistically significant difference found for each
... Show MoreThe aim of this study is to highlight the relationship between competitive intelligence and Entrepreneurial Performance by centralizing the strategic vigilance of a sample of civil faculties in Baghdad. The sample of the study was targeted at 10 Iraqi civil colleges, which consisted of (133) members of the faculty council of the faculties, the search data was collected using the questionnaire form as the main research tool. The results showed that the correlation and influence of competitive intelligence and strategic vigilance in the Entrepreneurial Performance, as well as the role of strategic vigilance as an intermediate variable between competitive intelligence and Entrepreneurial Performance.