By default, SessionID values are stored in a cookie.
However, you can also configure the application to store SessionID values in the URL for a "cookieless" session.
More clearly as below:-
1. In ASP.NET, you have a Session cookie.
2. This cookie is used to identify which session is yours, but doesn't actually contain the session information.
3. By default, ASP.NET will store session information in memory inside of the worker process (InProc), typically w3wp.exe.
4. There are other modes for storing session, such as Out of Proc and a SQL Server.
5. ASP.NET by default uses a cookie, but can be configured to be "cookieless" if you really need it; which instead stores your Session ID in the URL itself.
7. If your URL looked like this:
http://www.example.com/page.aspx
A cookieless URL would look like this:
http://www.example.com/(S(lit3py55t21z5v55vlm25s55))/page.aspx
Where lit3py55t21z5v55vlm25s55 is a session ID.
8. In Short, SessionID values are stored in a cookie and there session information is store in memory inside of the worker process (InProc), typically w3wp.exe.