Re: Security and validating a page
| From: | Richard Lynch | Date: | Thu, 04 Jan 2001 18:51:02 +0000 |
| Subject: | Re: Security and validating a page | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-32705@lists.php.net to get a copy of this message | ||
> I have a page in which I validate the code by re-entering the page after
> setting a hidden field. The Form uses the POST method, so the Credit
> Card number is not in the URL, but is this secure enough?
>
> Once I know all of the fields are complete, then I send it to the Credit
> Card facility via SSL.
NO!
Your entire routine for accepting the CC# must reside on an SSL server.
POST variables are no more safe than GET variables.
(Well, okay, Joe Sixpack and Betsy Buick won't see them in the URL to play
with, but any script kiddie can look inside your HTML to see POST vars.)
The whole point of SSL is that the data is scrambled in between the browser
and the server, and can only be descrambled by the browser and server. This
defeats a "wire tap" (which on the 'net is called "packet sniffing"). If
you're shuffling the CC# back and forth without SSL before you send it off
to the credit card facility, you're definitely defeating the whole purpose
of SSL in the first place.
You *MUST* have the FORM that the user sees to type in the CC#, and the
script that gets the CC# residing on an SSL server.