Freelancers Network
 
skill list top cap
Homepage
Join the Freelancer's Network
Update your details
Find a freelancer
Post a project
Find a project
Projects Archive
Post a job
Find a job
Jobs Archive
See Dan's Pages
See Andy's Pages
Link to this site
Resources
Join/Leave Forum
Forum Messages
+Additions+ Adverts
Advertising
Contact Us
Subscribe to our newsletter - enter your email address and hit return
Freelancers.net is owned and operated by Andy Stowell and Dan Winchester
skill list end cap
guru web hostcom

Find me again on Freelancers.net

RE: FN-FORUM: dB growth

date posted 22nd September 2006 10:22

You wouldn't be storing the session ID in the database, rather the session
data at the server end would contain the company ID. Besides, a properly
coded system would guard against SQL injection attacks (i.e. check that the
form fields contain only data and not SQL commands).

Dave.

__________________________________________________
Dave Boulden, Director. DA Media Limited
web: http://www.da-media.co.uk/
Tel: 01795 559456 Fax: 07092 011488




> -----Original Message-----
> From: [EMAIL REMOVED] [EMAIL REMOVED] On
> Behalf Of [EMAIL REMOVED]
>
>
> Dom,
>
> Sorry for appearing thick here security is obviously not my job.
>
> How do you use the encrypted session id to stop someone
> re-setting their company id, presumably I could use something like
>
> Set session("company_id")=nn where
> sessionid=01c4234c1f70a20aa90c9d78358c5472
>
> Bit of trial and error or using one of those terrifying tools
> they keep frightening me with at DDD days and I'd have the
> basic information needed to reset the appropriate variable to
> access another client's data.
>
> As I said I'm no security expert, just trying to learn/help.
>
> John
>
> -----Original Message-----
> From: [EMAIL REMOVED] [EMAIL REMOVED] On
> Behalf Of Dom Latter
> Sent: 21 September 2006 15:15
> To: Anslow, John
> Subject: Re: FN-FORUM: dB growth
>
>
> On Thursday 21 Sep 2006 1:18 pm, [EMAIL REMOVED] John wrote:
> > 1. set session("company_id")=someone else's company_id
>
> Session variables are keyed to the session ID and stored on
> the server, not the client. The session cookie looks like this
>
> Name PHPSESSID
> Value 01c4234c1f70a20aa90c9d78358c5472
> Host www.regalaunaexperiencia.es
> Path /
> Expires At End Of Session
>
> Reckon you can hack a 128 bit number?
>



Messages by Day
September 30th 2006
September 29th 2006
September 28th 2006
September 27th 2006
September 26th 2006
September 25th 2006
September 24th 2006
September 23rd 2006
September 22nd 2006
September 21st 2006
September 20th 2006
September 19th 2006
September 18th 2006
September 17th 2006
September 16th 2006
September 15th 2006
September 14th 2006
September 13th 2006
September 12th 2006
September 11th 2006
September 10th 2006
September 9th 2006
September 8th 2006
September 7th 2006
September 6th 2006
September 5th 2006
September 4th 2006
September 3rd 2006
September 2nd 2006
September 1st 2006


Messages by Month
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006


Messages by Year
2008
2007
2006
2005
2004
2003
2002
2001
2000