Software Interview Questions
Questions Answers Views Company eMail

4 down vote favorite share [g+] share [fb] share [tw] I am developing my site using server side sessions using redis as backend for saving the session. Now the issue which is bothering me is of user leaving the website without logging out. I mean user simply closes the browser which causes the cookie to be deleted. Now session of that user still exists on the server and will not be used again as new login requires creating a new session due to security reasons. To avoid the case where hacker steals the old cookie and use it after user login again with same old session id. In essence user leaves the website without explicitly logging out and his session will be deleted after certain time limit of inaccessibility. I am thinking time limit of 30-60 minutes. Also with every new request from user his cookie will also be updated to keep track of when the user last time accessed the site. But nowadays, people let site remain open for long time without accessing it. For example users open facebook and gmail in new tabs and forget about them for 2-3 hours and still they are not asked to login again. Is letting a 2-3 hours old cooke access the session secure? My concern is someone steals user cookie and use it 2-3 hours later. Thinking on this topic has also forced me to question how facebook manages security if user can use a session where they are not accessing it for long periods of time and still they remain logged in. Or is it not secure for me to keep logged in when am not accessing the site session for longer period of time? It can be the case also there is some pinging mechanism using which sites keep track of user having their site open in a browser and when browser closes they are notified and can work accordingly. My website is a social network and needs all those security and usage features which a social network may need. I am new to web security and web development in general and may be the case where my above questions may seem a little basic. If you feel that is the case kindly point to some good reference where I can read and find answers to my question.

NIIT,

1741

How to stimulate the people in the recruitment procces?

2893

I have 2 customers “Customer A” and “Customer B”.I need to create a sales order for both of them using ZOR sales doc type. Both need the same material m-01. But for customer “a” the item category of M-01 should be TAN and for “b” the item category is TANN. where should i do the configuration.in sap sd

IBM, Intelligroup,

3 7370

Hi can any bady tell me who provide QA,QTP,QC,training please let me know i need help i want get training thanks in advance

2 3893

What are different assignments we will do in SAP SD tab in the IMG and please let me know difference between the assignment & determination?

Wipro,

3 6093

what is ECC in sap bi?

2298

what is DBCONNECT AND UDCONNECT IN SAP BI?

1 8564

how to find the heap size is full in weblogic server?

DELL,

1 5262

what is lamda expression?

3 4741

Please provide me the the difference between Procure to Pay(P2P),Buy to Pay(B2P)and Invoice to Pay(I2P)

Cap Gemini,

2 20731

When concatenating two PDS can any one PDS can have empty dataset i.e without any value(Dummy).

2 6147

ioc vs dependency injection?

1909

Hi,My name is Saurabh I have done BMS & currently working in Wipro BPO (1 year). I want to pursue my career in SAP. As I am totally new in the IT field(no course & no experience) Please could you suggest whether to do a certification from Certified institutes or Non Certified institutes.What is the difference? Also, Is MBA necessary to do certification from Certified institutes?

1860

Should the user logged off... to assign the missing authorizations?

3 5370

what are the default arguments for pl/sql program?

1 4472


Un-Answered Questions { Software }

Which package has light weight components in java programming?

673


What is calloc in c?

661


Tell me why you use a static front page in wordpress?

103


What is configuration and monitoring dashboard?

59


What does important mean in css?

442






What are the functions of a Parser?

610


Explain the difference between the into and the set option in the exec cics receive map command?

558


Under what condition selecting sorted input in aggregator may fail the session?

663


What is a namespace in python?

490


What is the diffrence between a local-tx-datasource and a xa-datasource?

580


Where is apache installed windows?

482


How many lookup relationship fields can be created in an object?

290


What is the wait?

519


What is meant by authorization?

586


Why do we convert categorical variables into factor?

48