Please take our Survey
logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

RE: security: msg#00843

lib.binarycloud.devel

Subject: RE: security

Wouldn't it be best to run security like this:

User logs in, gets their session ID.

The system checks to ensure that that session is currently active, and
not spoofed, based on IP, Browser, OS type. And that the data coming
to/from that session, is what is should be exactly, without any other
input.

Basically saying that if the request was for table5, field6, row7, only
that could be inputted/extracted. Any addition information, would
create a security violation alert, alerting both the user, and site
admin.

I wouldn't want someone with a valid session, to get info from table5,
field6, row8, just because he altered the URL.

Just a thought.

Michael

-----Original Message-----
From: Albert Lash
[mailto:alash-tHZu4XM3tDUE4HWnolEugJowlv4uC7bZ@xxxxxxxxxxxxxxxx]
Sent: Friday, May 31, 2002 11:02 AM
To: dev-zNu2Yekbks92Brm55YPRC3dfcadvtA/q@xxxxxxxxxxxxxxxx
Subject: [binarycloud-dev] security


Hey Alex,

A couple of days ago I was talking about how to return user specific
data, the $client->user_id thing to incorporate into a SQL query. I was
thinking it would be great practice to link a random id to each user.
This in essence doesn't prevent break-ins, but makes it harder to guess
what anothers users name or id would be. It seems like such a bad idea
to use an auto increment index as user id's.

- Alby


---------------------------------------------------------------------
To unsubscribe, e-mail:
dev-unsubscribe-zNu2Yekbks92Brm55YPRC3dfcadvtA/q@xxxxxxxxxxxxxxxx
For additional commands, e-mail:
dev-help-zNu2Yekbks92Brm55YPRC3dfcadvtA/q@xxxxxxxxxxxxxxxx

Attachment: smime.p7s
Description: S/MIME cryptographic signature

<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
version-control...    qnx.openqnx.dev...    redhat.rhn.user...    ietf.openpgp/20...    mail.mutt.user/...    web.microformat...    java.sync4j.use...    education.ezpro...    user-groups.blu...    solaris.manager...    org.fitug.debat...    technology.erps...    politics.activi...    linux.redhat.fe...    bug-tracking.ma...    xfce.user/2004-...    hams/2004-11/ms...    kde.users.pim/2...    culture.cooking...    freebsd.devel.x...    gnu.m4.adhoc/20...    ngpt.user/2002-...    apple.fink.deve...   
Home | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe

Navigation