Re: Re: B2B site
| From: | Michael Hall | Date: | Fri, 29 Sep 2000 11:03:52 +0000 |
| Subject: | Re: Re: B2B site | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-18032@lists.php.net to get a copy of this message | ||
Cookies and/or session management aren't what I was getting at. Consider
these scenarios:
(1) Mr Badguy puts 5Mb of data into one of your form input fields resulting
in a "buffer overflow attack" on your server
(2) Mr Badguy puts input including commands like "..../cat%20/etc/passwd"
(show me your password file) into a form field
Is your server well configured? Will your PHP code pick this kind of input
up before it does any damage?
Michael Hall
----- Original Message -----
From: Abe Asghar <abe@fish.tm>
To: Michael Hall <mulgaweb@mulga.com.au>; <php-general@lists.php.net>
Sent: Friday, September 29, 2000 8:06 PM
Subject: Re: [PHP] Re: B2B site
> Yes. The forms will be validated - cookies or sessions will be used. And
> our server is managed outside and it's security is also managed outside.
My
> concer is the working of the web site.
>
> Thanks
> Abe
> ----- Original Message -----
> From: "Michael Hall" <mulgaweb%mulga.com.au@octa4.net.au>
> To: "Abe Asghar" <abe@fish.tm>
> Sent: Friday, September 29, 2000 11:32 AM
> Subject: Re: [PHP] B2B Site
>
>
> > I am in no way an expert about security, but I think it is true to say
> that
> > secure/encrypted connections like SSL can give a false sense of security
> > because they probably do little to protect data sitting on a badly
> > configured server. They should be treated as only one part of a
> > comprehensive security approach ... so yes, there probably are great
deal
> > more security concerns that you should be thinking about. Like your
forms
> > for example ... will you be validating input adequately?
> >
> > Michael Hall
> >
> > ----- Original Message -----
> > From: Abe Asghar <abe@fish.tm>
> > To: <php-general@lists.php.net>
> > Sent: Friday, September 29, 2000 7:26 PM
> > Subject: [PHP] B2B Site
> >
> >
> > > Hi Guys,
> > >
> > > It looks pretty likely that I will be working on a site with a
catalogue
> > > that allows suppliers and buyers to log in and add products.
> > >
> > > The site must be secure in how it handles people logging in. If the
> site
> > is
> > > put over a secure connection then does that mean that it is secure as
> this
> > > encrytps data between the server and the browser. Then when the users
> > want
> > > to download orders they can log in and download them over a secure
> > > connection.
> > >
> > > I will not be sending them the order by email as this is not secure.
> Does
> > > this sound genereally secure enough?
> > >
> > > Or are there a great deal more security concerns that I should be
> thinking
> > > about.
> > >
> > > Thanks,
> > >
> > > Abe
> > >
> > >
> > > --
> > > PHP General Mailing List (http://www.php.net/)
> > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > > For additional commands, e-mail: php-general-help@lists.php.net
> > > To contact the list administrators, e-mail:
php-list-admin@lists.php.net
> > >
> >
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>