Session ID not random enough - ASP.NET
问题 UPDATE We eventually had a meeting with some programmers on the Acunetix team and they realized there may be a few bugs in their code that are causing this to be displayed in the scan as more of an issue than it actually may be. The general consensus was to ignore the scan results and use the out-of-the-box ASP.NET Session ID generation as it should be secure enough for our site. @Vasile Bujac since your answer was the only one and mentioned using the ASP.NET standard solution I took that as