RE: [PHP-DB] Passing values

From: Date: Mon, 21 Aug 2000 16:40:02 +0000
Subject: RE: [PHP-DB] Passing values
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-2233@lists.php.net to get a copy of this message
On Mon, 21 Aug 2000 fabrizio.ermini@sysdat.it wrote: > On 21 Aug 2000, at 11:07, Chad Day wrote: > > I always see this reply.. pass hidden form fields.. but users can > download > > the html, modify it client-side, and send back false data.. so I don't think > > this is a very secure way of passing data between pages. What would work > > better (besides session variables?)? > > > Yep, passing values in hidden form is far from being secure. If you > feel that you need a little protection there are some techiques that > you can use, however (besides session variables, as you said ;-)): > > -) use some mean to render data passed unobvious to modify. I.E. > instead of using > <input type=hidden name=price value=10000> > you could use something like > <input type=hidden name=xcz value=<? echo > some_encoding_function("10000"); ?> > (of course you would decode the value passed before using it). > This way it could be rather difficult for a malicious user understand > how he could modify the data passed to achieve some result. If you're going to do this, please don't use your own "encoding" function. Use mcrypt with DES or something -- an algorithm that was written by those with a knack for cryptography. Some people come up with their own hashing functions/encryption functions, and they're usually very lame and easily broken -- and think who would be clever enough to try to spoof your page -- perhaps the same people who would also try to break your encryption. :-) > -) always check the $HTTP_REFERER to see from where the data > passed to the script arrive. If it's not the page that it's intented to > be, send a Error 500 response or something like that. > -) If this is still not enough for you, use PHP to implement other > security techniques like one-time password, strong crypto, > whatever. Malicious user can see what is exchanged, but cannot > see the PHP code that process it (since it's server-side), so there > is really little he can do. > > HTH > > > /\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/ > > Fabrizio Ermini Alternate E-mail: > C.so Umberto, 7 faermini@tin.it > loc. Meleto Valdarno Mail on GSM: (keep it short!) > 52020 Cavriglia (AR) faermini@sms.tin.it > >

« previous php.db (#2233) next »