List: websecurity@lists.webappsec.org
From: Thomas Ptacek
Re: [WEB SECURITY] SSO request hijack
Wed, Mar 14, 2012 6:49 PM
.
>
> Second, placing data in the URL is considered unwise, as that data is
> logged in various places like proxies, browser history and web logs.
> Should an attacker gain access to any one of those items, they could
> replay the session within the three minute validity period.
>
> Third, if a user controls any part of the XML data, you might be
> subject