Quantcast
Channel: Security Vulnerability
Viewing all articles
Browse latest Browse all 317

Same auth cookie send to different users

$
0
0

Hello,

first I want to apology to send new question in Visual Studio General Questions. But I cannot see ASP.NET forum. I would like to ask you if there is someone who solved problem with auth cookie. 

We have two IIS servers and load balancer which switch users between these servers. We use Form authentication to log in user. In login there is created auth cookie and it is sent back to browser (client). When user creates request then this cookie is send back to server and user is authenticate. It works fine. But there is some situation when user is switched to context another user. I don't understand how. User is switched means that user is logged as another user. 

I take a long time to investigate it and learn about cookie authentication. I think there must be some place where cookie from another user is send back to different user. But there is one place where auth cookie is send back to client only. This is login page. 

My question is if this behavior could be caused by IIS servers. 

Thank you.


Viewing all articles
Browse latest Browse all 317

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>