Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #17497

Re: Ecommerce site - how?

From "R.Wieser" <address@not.available>
Newsgroups comp.lang.php
Subject Re: Ecommerce site - how?
Date 2017-06-27 12:27 +0200
Organization Aioe.org NNTP Server
Message-ID <oitbtf$jts$2@gioia.aioe.org> (permalink)
References <d2223e3b-f44c-4ef7-b55a-94e012d85a95@googlegroups.com><oiodsn$pud$1@gioia.aioe.org><PcqdnRTWK6vXeM3EnZ2dnUU7-X3NnZ2d@posted.internetamerica><oir89b$187l$1@gioia.aioe.org> <oirani$2jp$1@solani.org><oirgtl$1po2$1@gioia.aioe.org> <erd6dvFhfi0U1@mid.individual.net><oirtfe$h7d$2@gioia.aioe.org> <eread9FnlrfU1@mid.individual.net>

Show all headers | View raw


J.O.

> it don't have to benefit the shopper, it can benefit a third party.

As I already said, how ?

> Thought of sending more than just product id, the code that is on
> the e-commerce site may have a flaw which makes it possible to
> send a value not usually stored in the cookie to make the site to do
> something else,

Ah, the "lets not answer the question, but trum up some other problems"
method.  Nope, rejected.   Explain how changing the product IDs in such a
cookie benefits anyone, or admit defeat (in this regard).

After that I'm open to hearing about which other kinds of data you also want
to shuttle around in cookies, and how that could be exploited (to which my
answer would most likely be to not send those to the user, but use a PHP
session and store them in there. :-) )

> The session cookie do not automatically get "destroyed" just for you
> leave a site, it live the set life span it has, some sites uses a short
> life span and other a long.

Gee... Do I hear an echo ?   Yes, it must be, as that is exactly what I
explained in my previous message. :-)

Read that part again bub, and than you can maybe acknowledge that having a
cookie with a session ID on *your* computer does not mean that the PHP
session will still be available on *their* computer (but its good enough to
track you :-) )

> Hint: no login needed as long as you visit the site before the
> session cookie expires.

Wrong.  See above.

And you're funny: you already told me that the contents of a cookie are easy
to alter (even by a third party), but you *still* think its a good idea to
accept it to authenticate you when you reconnect (with a different IP...) to
the site.   Make up you mind bub, either the cookie contents are secure, or
they aren't.  You can't have it both ways.

> JavaScript and iframes don't automatically make a page insecure,

True.  Its just the 90% of all other cases which could cause a problem. :-)

> if you do follow the guidelines at OWASP then your page will has less
> risks of normal vulnerabilities

"less risk" and "normal vunerabilities".  You really sound like some (scum)
marketoid there, selling snake oil.  :-(

Regards,
Rudy Wieser


-- Origional message:
J.O. Aho <user@example.net> schreef in berichtnieuws
eread9FnlrfU1@mid.individual.net...
> On 06/26/17 23:14, R.Wieser wrote:
> > J.O.
> >
> >> Which would be possible to tamper ...
> >
> > Absolutily.
> >
> > Just one question: how would he person who is shopping at the moment
benefit
> > from altering the article codes of the products he has selected himself
?
>
> it don't have to benefit the shopper, it can benefit a third party.
>
> >> ... and give another attack vector
> >
> > Pray tell, I'm rather interrested in hearing how changing product-id "X"
> > into "Y" can be exploited.
>
> Thought of sending more than just product id, the code that is on the
> e-commerce site may have a flaw which makes it possible to send a value
> not usually stored in the cookie to make the site to do something else,
> for example "admin=true" and the user may suddenly be the administrator
> of the whole site.
>
>
> >> Session cookie can have a long lifespan too, so the user could come
> >> back and continue with what is stored in the session.
> >
> > Depending on what you mean with "sesssion cookie" here I can agree, but
as
> > easily disagree with you.
> >
> > As you have complained about how easy it would be to "attack" data
stored in
> > a cookie I'm going to assume hat you ment a "session cookie" as in a
cookie
> > which holds nothing more than a session-ID (correct me if I'm wrong)..
> >
> > Yes, both a cookie and thus the a session ID stored in it can live for
the
> > longest time (depending on the lifetime the website has defined for the
> > cookie-data ofcourse -- which, for a shopping cart of an e-commerce
site,
> > will be rather short), but the PHP session its referring to will be
> > destroyed shortly after you leave the server, making that stored ID
rather
> > worthless.
>
> The session cookie do not automatically get "destroyed" just for you
> leave a site, it live the set life span it has, some sites uses a short
> life span and other a long. Depending on your browser settings, you can
> let the cookie survive a close down of the browser.
>
> > And although resuming a *shopping* session will be possible, it
certainly
> > will not be done by using that session-ID.  hint: logging in.
>
> Hint: no login needed as long as you visit the site before the session
> cookie expires.
>
> >> If you are interested in learning take a look at OWASP.
> >
> > Nope, not interrested in learning.  No sirree, not at all! /s
> >
> > I just took a quick look at that site (www.owasp.org).   The first thing
I
> > noticed was iframes and JS, both to external sites.   For a fricking
> > *security* minded site.  Don't make me laugh please.  Idiots.
>
> JavaScript and iframes don't automatically make a page insecure, if you
> do follow the guidelines at OWASP then your page will has less risks of
> normal vulnerabilities, no matte how your site is generated.
>
> --
>
>  file://Aho

Back to comp.lang.php | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Ecommerce site - how? bit-naughty@hotmail.com - 2017-06-25 05:42 -0700
  Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-25 15:30 +0200
    Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-25 16:03 +0200
    Re: Ecommerce site - how? gordonb.y152t@burditt.org (Gordon Burditt) - 2017-06-26 05:43 -0500
      Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 17:12 +0200
        Re: Ecommerce site - how? "Christoph M. Becker" <cmbecker69@arcor.de> - 2017-06-26 17:54 +0200
          Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 19:40 +0200
            Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-26 21:42 +0200
              Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 23:14 +0200
                Re: Ecommerce site - how? "Christoph M. Becker" <cmbecker69@arcor.de> - 2017-06-27 00:28 +0200
                Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 10:48 +0200
                Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-27 07:56 +0200
                Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 12:27 +0200
                Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-27 19:15 +0200
                Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 22:01 +0200
                Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-28 07:07 +0200
                Re: Ecommerce site - how? Gordon Burditt <gordon@hammy.burditt.org> - 2017-06-30 17:08 -0500
        Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-26 18:29 +0200
          Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 19:17 +0200
            Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-26 13:34 -0400
              Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 20:11 +0200
                Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-26 21:31 +0200
                Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-26 22:29 +0200
                Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-27 07:19 +0200
                Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 11:24 +0200
                Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-27 19:43 +0200
                Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 23:09 +0200
                Re: Ecommerce site - how? "J.O. Aho" <user@example.net> - 2017-06-28 07:12 +0200
                Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-27 21:10 -0400
                Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-26 16:32 -0400
                Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 10:30 +0200
                Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-27 08:38 -0400
                Re: Ecommerce site - how? "R.Wieser" <address@not.available> - 2017-06-27 17:47 +0200
                Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-27 12:16 -0400
                Re: Ecommerce site - how? gordonb.bytf1@burditt.org (Gordon Burditt) - 2017-06-29 18:16 -0500
                Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-29 20:41 -0400
                Re: Ecommerce site - how? gordonb.99a3p@burditt.org (Gordon Burditt) - 2017-06-29 23:39 -0500
                Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-30 07:28 -0400
                Re: Ecommerce site - how? Stefan+Usenet@Froehlich.Priv.at (Stefan Froehlich) - 2017-06-30 13:48 +0000
                Re: Ecommerce site - how? gordonb.gcghn@burditt.org (Gordon Burditt) - 2017-06-30 16:15 -0500
                Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-30 22:35 -0400
                Re: Ecommerce site - how? Richard Damon <Richard@Damon-Family.org> - 2017-06-29 23:46 -0400
        Re: Ecommerce site - how? gordonb.d2wed@burditt.org (Gordon Burditt) - 2017-06-29 17:32 -0500
  Re: Ecommerce site - how? bit-naughty@hotmail.com - 2017-06-27 10:58 -0700
    Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-06-27 15:34 -0400
    Re: Ecommerce site - how? gordonb.4psc7@burditt.org (Gordon Burditt) - 2017-06-30 16:55 -0500
      Re: Ecommerce site - how? bit-naughty@hotmail.com - 2017-07-01 03:03 -0700
        Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-07-01 09:30 -0400
        Re: Ecommerce site - how? Jerry Stuckle <jstucklex@attglobal.net> - 2017-07-01 09:34 -0400

csiph-web