Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #17497
| From | "R.Wieser" <address@not.available> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | Re: Ecommerce site - how? |
| Date | 2017-06-27 12:27 +0200 |
| Organization | Aioe.org NNTP Server |
| Message-ID | <oitbtf$jts$2@gioia.aioe.org> (permalink) |
| References | <d2223e3b-f44c-4ef7-b55a-94e012d85a95@googlegroups.com><oiodsn$pud$1@gioia.aioe.org><PcqdnRTWK6vXeM3EnZ2dnUU7-X3NnZ2d@posted.internetamerica><oir89b$187l$1@gioia.aioe.org> <oirani$2jp$1@solani.org><oirgtl$1po2$1@gioia.aioe.org> <erd6dvFhfi0U1@mid.individual.net><oirtfe$h7d$2@gioia.aioe.org> <eread9FnlrfU1@mid.individual.net> |
J.O. > it don't have to benefit the shopper, it can benefit a third party. As I already said, how ? > Thought of sending more than just product id, the code that is on > the e-commerce site may have a flaw which makes it possible to > send a value not usually stored in the cookie to make the site to do > something else, Ah, the "lets not answer the question, but trum up some other problems" method. Nope, rejected. Explain how changing the product IDs in such a cookie benefits anyone, or admit defeat (in this regard). After that I'm open to hearing about which other kinds of data you also want to shuttle around in cookies, and how that could be exploited (to which my answer would most likely be to not send those to the user, but use a PHP session and store them in there. :-) ) > The session cookie do not automatically get "destroyed" just for you > leave a site, it live the set life span it has, some sites uses a short > life span and other a long. Gee... Do I hear an echo ? Yes, it must be, as that is exactly what I explained in my previous message. :-) Read that part again bub, and than you can maybe acknowledge that having a cookie with a session ID on *your* computer does not mean that the PHP session will still be available on *their* computer (but its good enough to track you :-) ) > Hint: no login needed as long as you visit the site before the > session cookie expires. Wrong. See above. And you're funny: you already told me that the contents of a cookie are easy to alter (even by a third party), but you *still* think its a good idea to accept it to authenticate you when you reconnect (with a different IP...) to the site. Make up you mind bub, either the cookie contents are secure, or they aren't. You can't have it both ways. > JavaScript and iframes don't automatically make a page insecure, True. Its just the 90% of all other cases which could cause a problem. :-) > if you do follow the guidelines at OWASP then your page will has less > risks of normal vulnerabilities "less risk" and "normal vunerabilities". You really sound like some (scum) marketoid there, selling snake oil. :-( Regards, Rudy Wieser -- Origional message: J.O. Aho <user@example.net> schreef in berichtnieuws eread9FnlrfU1@mid.individual.net... > On 06/26/17 23:14, R.Wieser wrote: > > J.O. > > > >> Which would be possible to tamper ... > > > > Absolutily. > > > > Just one question: how would he person who is shopping at the moment benefit > > from altering the article codes of the products he has selected himself ? > > it don't have to benefit the shopper, it can benefit a third party. > > >> ... and give another attack vector > > > > Pray tell, I'm rather interrested in hearing how changing product-id "X" > > into "Y" can be exploited. > > Thought of sending more than just product id, the code that is on the > e-commerce site may have a flaw which makes it possible to send a value > not usually stored in the cookie to make the site to do something else, > for example "admin=true" and the user may suddenly be the administrator > of the whole site. > > > >> Session cookie can have a long lifespan too, so the user could come > >> back and continue with what is stored in the session. > > > > Depending on what you mean with "sesssion cookie" here I can agree, but as > > easily disagree with you. > > > > As you have complained about how easy it would be to "attack" data stored in > > a cookie I'm going to assume hat you ment a "session cookie" as in a cookie > > which holds nothing more than a session-ID (correct me if I'm wrong).. > > > > Yes, both a cookie and thus the a session ID stored in it can live for the > > longest time (depending on the lifetime the website has defined for the > > cookie-data ofcourse -- which, for a shopping cart of an e-commerce site, > > will be rather short), but the PHP session its referring to will be > > destroyed shortly after you leave the server, making that stored ID rather > > worthless. > > The session cookie do not automatically get "destroyed" just for you > leave a site, it live the set life span it has, some sites uses a short > life span and other a long. Depending on your browser settings, you can > let the cookie survive a close down of the browser. > > > And although resuming a *shopping* session will be possible, it certainly > > will not be done by using that session-ID. hint: logging in. > > Hint: no login needed as long as you visit the site before the session > cookie expires. > > >> If you are interested in learning take a look at OWASP. > > > > Nope, not interrested in learning. No sirree, not at all! /s > > > > I just took a quick look at that site (www.owasp.org). The first thing I > > noticed was iframes and JS, both to external sites. For a fricking > > *security* minded site. Don't make me laugh please. Idiots. > > JavaScript and iframes don't automatically make a page insecure, if you > do follow the guidelines at OWASP then your page will has less risks of > normal vulnerabilities, no matte how your site is generated. > > -- > > file://Aho
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Ecommerce site - how? bit-naughty@hotmail.com - 2017-06-25 05:42 -0700
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-25 15:30 +0200
Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-25 16:03 +0200
Re: Ecommerce site - how? gordonb.y152t@burditt.org (Gordon Burditt) - 2017-06-26 05:43 -0500
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 17:12 +0200
Re: Ecommerce site - how? "Christoph M. Becker" <cmbecker69@arcor.de> - 2017-06-26 17:54 +0200
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 19:40 +0200
Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-26 21:42 +0200
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 23:14 +0200
Re: Ecommerce site - how? "Christoph M. Becker" <cmbecker69@arcor.de> - 2017-06-27 00:28 +0200
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 10:48 +0200
Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-27 07:56 +0200
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 12:27 +0200
Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-27 19:15 +0200
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 22:01 +0200
Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-28 07:07 +0200
Re: Ecommerce site - how? Gordon Burditt <gordon@hammy.burditt.org> - 2017-06-30 17:08 -0500
Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-26 18:29 +0200
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 19:17 +0200
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-26 13:34 -0400
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 20:11 +0200
Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-26 21:31 +0200
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 22:29 +0200
Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-27 07:19 +0200
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 11:24 +0200
Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-27 19:43 +0200
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 23:09 +0200
Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-28 07:12 +0200
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-27 21:10 -0400
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-26 16:32 -0400
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 10:30 +0200
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-27 08:38 -0400
Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 17:47 +0200
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-27 12:16 -0400
Re: Ecommerce site - how? gordonb.bytf1@burditt.org (Gordon Burditt) - 2017-06-29 18:16 -0500
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-29 20:41 -0400
Re: Ecommerce site - how? gordonb.99a3p@burditt.org (Gordon Burditt) - 2017-06-29 23:39 -0500
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-30 07:28 -0400
Re: Ecommerce site - how? Stefan+Usenet@Froehlich.Priv.at (Stefan Froehlich) - 2017-06-30 13:48 +0000
Re: Ecommerce site - how? gordonb.gcghn@burditt.org (Gordon Burditt) - 2017-06-30 16:15 -0500
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-30 22:35 -0400
Re: Ecommerce site - how? Richard Damon <Richard@Damon-Family.org> - 2017-06-29 23:46 -0400
Re: Ecommerce site - how? gordonb.d2wed@burditt.org (Gordon Burditt) - 2017-06-29 17:32 -0500
Re: Ecommerce site - how? bit-naughty@hotmail.com - 2017-06-27 10:58 -0700
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-27 15:34 -0400
Re: Ecommerce site - how? gordonb.4psc7@burditt.org (Gordon Burditt) - 2017-06-30 16:55 -0500
Re: Ecommerce site - how? bit-naughty@hotmail.com - 2017-07-01 03:03 -0700
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-07-01 09:30 -0400
Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-07-01 09:34 -0400
csiph-web