RE: [PHP-DB] Passing values

From: Date: Mon, 21 Aug 2000 15:28:08 +0000
Subject: RE: [PHP-DB] Passing values
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-2228@lists.php.net to get a copy of this message
On 21 Aug 2000, at 11:07, Chad Day wrote: > I always see this reply.. pass hidden form fields.. but users can download > the html, modify it client-side, and send back false data.. so I don't think > this is a very secure way of passing data between pages. What would work > better (besides session variables?)? > Yep, passing values in hidden form is far from being secure. If you feel that you need a little protection there are some techiques that you can use, however (besides session variables, as you said ;-)): -) use some mean to render data passed unobvious to modify. I.E. instead of using <input type=hidden name=price value=10000> you could use something like <input type=hidden name=xcz value=<? echo some_encoding_function("10000"); ?> (of course you would decode the value passed before using it). This way it could be rather difficult for a malicious user understand how he could modify the data passed to achieve some result. -) always check the $HTTP_REFERER to see from where the data passed to the script arrive. If it's not the page that it's intented to be, send a Error 500 response or something like that. -) If this is still not enough for you, use PHP to implement other security techniques like one-time password, strong crypto, whatever. Malicious user can see what is exchanged, but cannot see the PHP code that process it (since it's server-side), so there is really little he can do. HTH /\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/ Fabrizio Ermini Alternate E-mail: C.so Umberto, 7 faermini@tin.it loc. Meleto Valdarno Mail on GSM: (keep it short!) 52020 Cavriglia (AR) faermini@sms.tin.it

« previous php.db (#2228) next »