Click here to Skip to main content
16,022,060 members
Please Sign up or sign in to vote.
1.00/5 (1 vote)
See more:
Please assist in this query.The application did not invalidate the ASP.NET SESSION upon logout. The same ASP.NET can be used to replay the same request.We are able to clear the ASP.NET Session Id in the client side and getting new Id for new request however if we store previous value of ASP.NET_Session Id and update the value in the request using F12 then users are able to access application. 


What I have tried:

We tried to clear session by calling Session.abandon and we are able to clear the session id in Client side.
Posted

This content, along with any associated source code and files, is licensed under The Code Project Open License (CPOL)



CodeProject, 20 Bay Street, 11th Floor Toronto, Ontario, Canada M5J 2N8 +1 (416) 849-8900