Re: Re: B2B site

From: Date: Fri, 29 Sep 2000 11:03:52 +0000
Subject: Re: Re: B2B site
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-18032@lists.php.net to get a copy of this message
Cookies and/or session management aren't what I was getting at. Consider these scenarios: (1) Mr Badguy puts 5Mb of data into one of your form input fields resulting in a "buffer overflow attack" on your server (2) Mr Badguy puts input including commands like "..../cat%20/etc/passwd" (show me your password file) into a form field Is your server well configured? Will your PHP code pick this kind of input up before it does any damage? Michael Hall ----- Original Message ----- From: Abe Asghar <abe@fish.tm> To: Michael Hall <mulgaweb@mulga.com.au>; <php-general@lists.php.net> Sent: Friday, September 29, 2000 8:06 PM Subject: Re: [PHP] Re: B2B site > Yes. The forms will be validated - cookies or sessions will be used. And > our server is managed outside and it's security is also managed outside. My > concer is the working of the web site. > > Thanks > Abe > ----- Original Message ----- > From: "Michael Hall" <mulgaweb%mulga.com.au@octa4.net.au> > To: "Abe Asghar" <abe@fish.tm> > Sent: Friday, September 29, 2000 11:32 AM > Subject: Re: [PHP] B2B Site > > > > I am in no way an expert about security, but I think it is true to say > that > > secure/encrypted connections like SSL can give a false sense of security > > because they probably do little to protect data sitting on a badly > > configured server. They should be treated as only one part of a > > comprehensive security approach ... so yes, there probably are great deal > > more security concerns that you should be thinking about. Like your forms > > for example ... will you be validating input adequately? > > > > Michael Hall > > > > ----- Original Message ----- > > From: Abe Asghar <abe@fish.tm> > > To: <php-general@lists.php.net> > > Sent: Friday, September 29, 2000 7:26 PM > > Subject: [PHP] B2B Site > > > > > > > Hi Guys, > > > > > > It looks pretty likely that I will be working on a site with a catalogue > > > that allows suppliers and buyers to log in and add products. > > > > > > The site must be secure in how it handles people logging in. If the > site > > is > > > put over a secure connection then does that mean that it is secure as > this > > > encrytps data between the server and the browser. Then when the users > > want > > > to download orders they can log in and download them over a secure > > > connection. > > > > > > I will not be sending them the order by email as this is not secure. > Does > > > this sound genereally secure enough? > > > > > > Or are there a great deal more security concerns that I should be > thinking > > > about. > > > > > > Thanks, > > > > > > Abe > > > > > > > > > -- > > > PHP General Mailing List (http://www.php.net/) > > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > > > For additional commands, e-mail: php-general-help@lists.php.net > > > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > > > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#18032) next »