ASP.NET Misconfiguration: Excessive Session Timeout
Abstract:Anoverlylongauthenticationtimeoutgivesattackersmoretimetopotentiallycompromiseuseraccounts.Explanation:Thelongerasessionstaysopen,thelargerthewindowofopportunityanattackerhastocompromiseusera