RE: [PHP-DB] Passing values
| From: | fabrizio dot ermini at sysdat dot it | Date: | Mon, 21 Aug 2000 15:28:08 +0000 |
| Subject: | RE: [PHP-DB] Passing values | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-2228@lists.php.net to get a copy of this message | ||
On 21 Aug 2000, at 11:07, Chad Day wrote:
> I always see this reply.. pass hidden form fields.. but users can
download
> the html, modify it client-side, and send back false data.. so I don't think
> this is a very secure way of passing data between pages. What would work
> better (besides session variables?)?
>
Yep, passing values in hidden form is far from being secure. If you
feel that you need a little protection there are some techiques that
you can use, however (besides session variables, as you said ;-)):
-) use some mean to render data passed unobvious to modify. I.E.
instead of using
<input type=hidden name=price value=10000>
you could use something like
<input type=hidden name=xcz value=<? echo
some_encoding_function("10000"); ?>
(of course you would decode the value passed before using it).
This way it could be rather difficult for a malicious user understand
how he could modify the data passed to achieve some result.
-) always check the $HTTP_REFERER to see from where the data
passed to the script arrive. If it's not the page that it's intented to
be, send a Error 500 response or something like that.
-) If this is still not enough for you, use PHP to implement other
security techniques like one-time password, strong crypto,
whatever. Malicious user can see what is exchanged, but cannot
see the PHP code that process it (since it's server-side), so there
is really little he can do.
HTH
/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/
Fabrizio Ermini Alternate E-mail:
C.so Umberto, 7 faermini@tin.it
loc. Meleto Valdarno Mail on GSM: (keep it short!)
52020 Cavriglia (AR) faermini@sms.tin.it