Thanks for providing this info, Lawrence. Does your response to Requirement #8 address the Predictable Cookie Session ID vulnerability I have seen associated with cartID sessions? In particular, the warning of Low entropy: The cookie was found to have only 23.2534966642115 bits of entropy.
↧