tomcat的 sessionid充值,很实用哟 http://bao231.iteye.com/blog/1164437 固定SessionID漏洞 http://www.iteye.com/topic/840876/