Reply
Old 06-22-2006, 10:49 AM ASP Security
Skilled Talker

Posts: 95
Trades: 0
Huy guys.

I'm developing a site that Using ASP vbscript. This site simply pulls information back from a DB.

It uses the request.servervariable.("LOGON_USER") to figure out which user to pull back information in. for example if i log on to my computer and then visit the site it show my info. if you did it it would show your info.

Now these has got to be secure so i cant see yours and you cant see mine.

All the security is controlled by the request.servervariable.("LOGON_USER") how easy it for people to hack into this and pretend to be some one else?

edit: Not asking how if possible its done. Just if it is possible and how to stop people doing it

Last edited by higginbt; 06-22-2006 at 12:25 PM..
higginbt is offline
Reply With Quote
View Public Profile
 
 
When You Register, These Ads Go Away!
Old 06-23-2006, 06:52 PM Re: ASP Security
chrishirst's Avatar
Super Moderator

Posts: 26,557
Location: Blackpool. UK
Trades: 0
to use LOGON_USER you have to be using Windows Authentication, which is pretty secure provided you aren't sending clear text passwords.
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
Growing old is mandatory - Growing up is optional
Code Samples | Crowded Nightclub? | Bits & Bobs
chrishirst is online now
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 06-26-2006, 12:13 PM Re: ASP Security
Skilled Talker

Posts: 95
Trades: 0
ok thanks. for the info
higginbt is offline
Reply With Quote
View Public Profile
 
Old 06-26-2006, 03:27 PM Re: ASP Security
Extreme Talker

Posts: 170
Name: XpIndia.Com
Trades: 0
what is your site link ?

Lemme check the security level and report back
XpIndia.Com is offline
Reply With Quote
View Public Profile
 
Old 06-27-2006, 05:54 AM Re: ASP Security
Skilled Talker

Posts: 95
Trades: 0
reply lol. Luckly its a page on the local intranet so its not open to just anyone
higginbt is offline
Reply With Quote
View Public Profile
 
Old 06-28-2006, 02:07 PM Re: ASP Security
sandbox's Avatar
Extreme Talker

Posts: 150
Trades: 0
Have you thought about protection from sql injection attacks? Something else you need to be aware of.
__________________
¦ geodesic domes ¦ bamboo t-shirts ¦How green is?
sandbox is offline
Reply With Quote
View Public Profile Visit sandbox's homepage!
 
Old 06-30-2006, 11:04 AM Re: ASP Security
Skilled Talker

Posts: 95
Trades: 0
Have i thought about SQL injection attacks!!?

in a word no.

what the hell are they
higginbt is offline
Reply With Quote
View Public Profile
 
Old 06-30-2006, 11:12 AM Re: ASP Security
Skilled Talker

Posts: 95
Trades: 0
ok. i know what they are now. Bloody hell thats quite scary.
But i dont have any input via users. Its all done via the Logon_user
higginbt is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to ASP Security
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML

 


Page generated in 0.11677 seconds with 13 queries