How to Increase entropy of CFID and CFTOKEN
Our application is scanned against penetration testing found below vulnarability -
comments from Vuln team-
this application does not validate attESSec cookie if CFID and CFTOKEN represents specific session. These two tokens are also used (in GET request parameters) in one specific automatic request by every user of the app after they are loggedin by Logon. These two cookies are therefore severely weakened in its confidentiality. In conclusion this vulnerability is consisting of: 1. low entropy in CFID and CFTOKEN 2. these two are sent in GET request by the app logic 3. there is no validation in attESSec and attESHr cookie and that severely weakens authentication
Resolution
Increase entropy of CFID and CFTOKEN
can you help me how to Increase entropy of CFID and CFTOKEN?
