Re: Security and validating a page

From: Date: Thu, 04 Jan 2001 18:51:02 +0000
Subject: Re: Security and validating a page
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-32705@lists.php.net to get a copy of this message
> I have a page in which I validate the code by re-entering the page after > setting a hidden field. The Form uses the POST method, so the Credit > Card number is not in the URL, but is this secure enough? > > Once I know all of the fields are complete, then I send it to the Credit > Card facility via SSL. NO! Your entire routine for accepting the CC# must reside on an SSL server. POST variables are no more safe than GET variables. (Well, okay, Joe Sixpack and Betsy Buick won't see them in the URL to play with, but any script kiddie can look inside your HTML to see POST vars.) The whole point of SSL is that the data is scrambled in between the browser and the server, and can only be descrambled by the browser and server. This defeats a "wire tap" (which on the 'net is called "packet sniffing"). If you're shuffling the CC# back and forth without SSL before you send it off to the credit card facility, you're definitely defeating the whole purpose of SSL in the first place. You *MUST* have the FORM that the user sees to type in the CC#, and the script that gets the CC# residing on an SSL server.

« previous php.general (#32705) next »