Re: Avoiding security issue with URL?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Mary Chipman (mchip_at_online.microsoft.com)
Date: 10/14/04


Date: Thu, 14 Oct 2004 14:54:52 -0400

A good resources that discusses all aspects of asp.net security is the
best practices whitepaper, which you can download from
http://www.microsoft.com/downloads/release.asp?ReleaseID=44047.

--Mary

On Wed, 13 Oct 2004 15:07:01 -0700, "Brett"
<Brett@discussions.microsoft.com> wrote:

>I use one page as a template and include a header, footer, and allow the main
>content area to change, based on a varible I supply via the URL. The
>variable holds a reference to another page and pulls it into the main page.
>Going from the main page to pageB will look like:
>
>index.asp?p=page
>
>Sometimes I append other URL parameters. These may be values, such as a
>user ID, that goes into the database to set conditions on a stored procedure.
> This is a security risk. Some one could manipulate this value and access
>another user's information. What are some examples of good security for this
>situation?
>
>Thanks,
>Brett



Relevant Pages

  • Re: Role based Forms Authentication (using Active Directory)
    ... I think I remember this being covered in the asp.net security best ... practices whitepaper, which you can download from ... >Thanks alot. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: File extensions spoofable in MSIE download dialog
    ... File extensions spoofable in MSIE download dialog ... I don't have internet explorer to test but rfc 2616 describes some "security considerations". ... > extension without a sign of EXE, and issue no Security Warning dialog ...
    (Bugtraq)
  • Re: Some mail opens a blank page
    ... YW, Dan, and thanks again for your valuable feedback. ... Save that download link and Product or User ID for CA Internet Security ... and then run the Removal Tool to rid the machine of all Norton crapware. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Short List of Security Questions
    ... Do you have a list of recommendations for windows? ... I think there are three separate aspects to PC security: ... get and download the latest Firefox and Thunderbird. ...
    (microsoft.public.security)
  • Re: Most recent OSX Viruses.
    ... Apple has updated Java for Mac OS X 10.5 and 10.6 addressing several ... security issues. ... Software Update in System Preferences or download directly from the Apple ...
    (comp.sys.mac.advocacy)