RE: [PHP-DB] Passing values
| From: | Dean Hall | Date: | Mon, 21 Aug 2000 16:40:02 +0000 |
| Subject: | RE: [PHP-DB] Passing values | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-2233@lists.php.net to get a copy of this message | ||
On Mon, 21 Aug 2000 fabrizio.ermini@sysdat.it wrote:
> On 21 Aug 2000, at 11:07, Chad Day wrote:
> > I always see this reply.. pass hidden form fields.. but users can
> download
> > the html, modify it client-side, and send back false data.. so I don't think
> > this is a very secure way of passing data between pages. What would work
> > better (besides session variables?)?
> >
> Yep, passing values in hidden form is far from being secure. If you
> feel that you need a little protection there are some techiques that
> you can use, however (besides session variables, as you said ;-)):
>
> -) use some mean to render data passed unobvious to modify. I.E.
> instead of using
> <input type=hidden name=price value=10000>
> you could use something like
> <input type=hidden name=xcz value=<? echo
> some_encoding_function("10000"); ?>
> (of course you would decode the value passed before using it).
> This way it could be rather difficult for a malicious user understand
> how he could modify the data passed to achieve some result.
If you're going to do this, please don't use your own
"encoding" function. Use mcrypt with DES or something -- an algorithm that
was written by those with a knack for cryptography. Some people come up
with their own hashing functions/encryption functions, and they're usually
very lame and easily broken -- and think who would be clever enough to try
to spoof your page -- perhaps the same people who would also try to break
your encryption. :-)
> -) always check the $HTTP_REFERER to see from where the data
> passed to the script arrive. If it's not the page that it's intented to
> be, send a Error 500 response or something like that.
> -) If this is still not enough for you, use PHP to implement other
> security techniques like one-time password, strong crypto,
> whatever. Malicious user can see what is exchanged, but cannot
> see the PHP code that process it (since it's server-side), so there
> is really little he can do.
>
> HTH
>
>
> /\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/
>
> Fabrizio Ermini Alternate E-mail:
> C.so Umberto, 7 faermini@tin.it
> loc. Meleto Valdarno Mail on GSM: (keep it short!)
> 52020 Cavriglia (AR) faermini@sms.tin.it
>
>