A session is a period of time linked to a user, which is initiated when he/she arrives at a web application and it ends when his/her browser is closed or after a certain time of inactivity. Attackers can hijack a user's session by exploiting session management vulnerabilities by means of session fixation and cross-site request forgery attacks.
Very often, session IDs are not only identification tokens, but also authenticators. This means that upon login, users are authenticated based on their credentials (e.g., usernames/passwords or digital certificates) and issued session IDs that will effectively serve as temporary static passwords for accessing their sessions. This makes session IDs a very appealing target for attackers. In many cases, an attacker who manages to obtain a valid ID of user’s session can use it to directly enter that session – often without arising user’s suspicion. A secure session management must be implemented in the development phase of web applications because it is the responsibility of the web application, and not the underlying web server.
Threat modeling is a systematic process that is used to identify threats and vulnerabilities in software and has become popular technique to help system designers think about the security threats that their system might face.
In this paper we design the threat modeling for session’s ID threat by using SeaMonster security modeling software, and then propose a secure session management that avoids the vulnerabilities. The proposed secure session management is designed to give trust authentication between the client and the server to avoid session hijacing attack by using both: server session’s ID and MAC address of the client.Visual Studio. Net 2008 is used in implementing the proposed system
Conventional identification of three coccoid green algae isolates was attempted to characterize the studied algae morphologically under compound microscope, which demonstrated confusional phenomenal convergence; all were classified microscopically as the green alga Chlorella vulgaris Beijerinck, 1890.
Phylogenetic studies were conducted to settle the argument about the phenotype by studying the genotype. Genotype the promising field in advance classification by using 18S rRNA and compared to GenBank database using to search the related sequences. The determined sequences showed high a similarity to the strains registered in GenBank.
&
... Show MoreCoronavirus disease (Covid-19) has threatened human life, so it has become necessary to study this disease from many aspects. This study aims to identify the nature of the effect of interdependence between these countries and the impact of each other on each other by designating these countries as heads for the proposed graph and measuring the distance between them using the ultrametric spanning tree. In this paper, a network of countries in the Middle East is described using the tools of graph theory.
Samples of the root nodules were collected to isolate different species of the genus Rhizobium from several leguminous plants; Trigonella foenum-graecum, Medicago sativa, Lens culinaris, Vigna mungo, Vicia faba, Phaseolus vulgaris, and Cicer arietinum, and based on their morphological, cultural, and biochemical characteristics, in addition to the identification of each isolate at the species level by amplified polymerase chain reaction (PCR) and using the sequencing of the nitrogenous bases of the 16S rRNA gene, it was identified as Sinrhizobium meliloti, Sinrhizobium meliloti, Bradyrhizobium elkanii, Rhizobium leguminosarium biovar viciae, Rhizobium leguminosarium biovar phaseoli and Mesorh
... Show MoreThe healthcare sector has traditionally been an early adopter of technological progress, gaining significant advantages, particularly in machine learning applications such as disease prediction. One of the most important diseases is stroke. Early detection of a brain stroke is exceptionally critical to saving human lives. A brain stroke is a condition that happens when the blood flow to the brain is disturbed or reduced, leading brain cells to die and resulting in impairment or death. Furthermore, the World Health Organization (WHO) classifies brain stroke as the world's second-deadliest disease. Brain stroke is still an essential factor in the healthcare sector. Controlling the risk of a brain stroke is important for the surviv
... Show MoreDrawbacks of Implementing Electronic Management in the Ministry of Education (A sample: Oman Educational Portal) from the Point of View of IT Staff. The study aimed at discovering the drawbacks of implementing electronic management in the Ministry of Education (a sample: Oman Educational Portal) from the point of view of IT staff, and that is by answering the following questions: - What are the main drawbacks (administrative, financial, technical and drawbacks related to human resources) that hinder implementing the electronic management in the Ministry of Education (a sample: Oman Educational Portal) from the point of view of IT staff? - Are there any statistical significance differences at the level (0.05) between study samples on the
... Show MoreDelays occur commonly in construction projects. Assessing the impact of delay is sometimes a contentious
issue. Several delay analysis methods are available but no one method can be universally used over another in
all situations. The selection of the proper analysis method depends upon a variety of factors including
information available, time of analysis, capabilities of the methodology, and time, funds and effort allocated to the analysis. This paper presents computerized schedule analysis programmed that use daily windows analysis method as it recognized one of the most credible methods, and it is one of the few techniques much more likely to be accepted by courts than any other method. A simple case study has been implement
Diyala River is one of the important rivers that provide water for the Governorate of Diyala. In this research, the morphology and sediment transport of this river were studied using HEC-Ras software. The selected length of the river in the present study is 193 km and extended from Diyala Weir to the confluence of Tigris River and Diyala River. The fieldwork period extended from June 2020 till August 2020, where suspended-load and bed-load samples were collected and surveyed some cross-sections. The one-dimensional sediment transport model has been calibrated for five years, from 2014 to 2019. The results were compared with the measured cross-sections in 2019, and the suitable value of (maximum depth
... Show MoreCompetitive swimming is a highly researched area and technological developments have aided advances in the understanding of the biomechanical principles that underpin these elements and govern propulsion. Moreover, those working in the sports field especially in swimming are interested in studying, analyzing, evaluating and developing motor skills by diagnosing the strengths and weaknesses of the skill, and accordingly, coaches and specialists correct these errors. The researchers chose this (Butterfly swimming) and the (arm length) is an important variable because the success of the stroke is greatly dependent on the propulsion generated from the arm pull, and swimmers with a longer arm span have a mechanical advantage with the resulting f
... Show MoreIncreasing world demand for renewable energy resources as wind energy was one of the goals behind research optimization of energy production from wind farms. Wake is one of the important phenomena in this field. This paper focuses on understanding the effect of angle of attack (α) on wake characteristics behind single horizontal axis wind turbines (HAWT). This was done by design three rotors different from each other in value of α used in the rotor design process. Values of α were (4.8˚,9.5˚,19˚). The numerical simulations were conducted using Ansys Workbench 19- Fluent code; the used turbulence model was (k-ω SST). The results showed that best value for extracted wind energy was at α=19˚, spread distance of wak
... Show MoreRoller Compacted Concrete (RCC) is a technology characterized mainly by the use of rollers for compaction; this technology achieves significant time and cost savings in the construction of dams and roads. The primary scope of this research is to study the durability and performance of roller compacted concrete that was constructed in the laboratory using roller compactor manufactured in local market. A total of (60) slab specimen of (38×38×10) cm was constructed using the roller device, cured for 28 days, then 180 sawed cubes and 180 beams are obtained from RCC slab. Then, the specimens are subjected to 60 cycles of freezing and thawing, sulfate attack test and wetting and drying. The degree of effect of the type of coarse aggregate (c
... Show More