CodeVerge.Net Beta


   Explore    Item Entry    Members      Register  Login  
NEWSGROUP
.NET
Algorithms-Data Structures
Asp.Net
C Plus Plus
CSharp
Database
HTML
Javascript
Linq
Other
Regular Expressions
VB.Net
XML

Free Download:




Zone: > NEWSGROUP > Asp.Net Forum > general_asp.net.security Tags:
Item Type: NewsGroup Date Entered: 11/16/2006 9:21:23 AM Date Modified: Subscribers: 0 Subscribe Alert
Rate It:
(NR, 0)
XPoints: N/A Replies: 0 Views: 35 Favorited: 0 Favorite
Can Reply:  No Members Can Edit: No Online: Yes
1 Items, 1 Pages 1 |< << Go >> >|
Messeiry
Asp.Net User
Parameter Tampering Solution, Session Id11/16/2006 9:21:23 AM

0/0

Dear All,

i have an e-commerce web application, i am applying payment with a third part, in order to do so the third parts gave me instructions, in order to do so. the instructions says that i have to create hidden field parameters and store amount and some valuable stuff.

the third parts also, requested that i create a hidden field with the session Id.

then when i click a button, the page is redirected to his website and then requested back.

well ....

my question is do the session id validation can prevent parameter manipulation.

 

Many Thanks

 


Mohamed ELMesseiry
Business System Analyst, Web Developer
1 Items, 1 Pages 1 |< << Go >> >|


Free Download:

Books:
Foundations of Security: What Every Programmer Needs to Know Authors: Neil Daswani, Christoph Kern, Anita Kesavan, Pages: 290, Published: 2007
Electronic Commerce: Concepts, Methodologies, Tools and Applications Authors: Annie Becker, S Ann Becker, Pages: 2522, Published: 2008
Hack Proofing ColdFusion: The Only Way to Stop a Hacker Is to Think Like One Authors: Syngress, Greg Meyer, Rob Rusher, Steven Casco, David An, Daryl Banttari, Pages: 512, Published: 2002
Network Processors: Architectures, Protocols, and Platforms Authors: Panos C. Lekkas, Pages: 456, Published: 2003
Trust, Privacy and Security in Digital Business: 4th International Conference, Trustbus 2007, Regensburg, Germany, September 3-7, 2007, Proceedings Authors: Costas Lambrinoudakis, Gunther Pernul, A. Min Tjoa, Pages: 289, Published: 2007
Security of Information and Networks: Proceedings of the First International Conference on Security of Information and Networks (SIN 2007) Authors: Atilla Elçi, S. Berna Ors, Bart Preneel, Pages: 386, Published: 2008
Encyclopedia of Library and Information Science: Volume 70 - Supplement 33 Authors: Allen Kent, Carolyn M. Hall, Harold Lancour, Pages: 500, Published: 2002
Secure Communications: Applications and Management Authors: Roger J. Sutton, Pages: 322, Published: 2002

Web:
Typical issues with webapplications v1.5 Parameter Tampering is a simple attack targeting the application business logic ... uses these authentication tokens (e.g., session ID in URL, cookie, etc. ...
Imperva Glossary | Parameter Tampering Parameter tampering is a simple attack targeting the application business logic. ... During a Web session, parameters are exchanged between the Web browser ...
Application Security Many web applications use cookies in order to save information (user id, ... In a certain site, parameter tampering with the session token produced a page ...
SYSTEMS AND METHODS FOR DETECTION OF SESSION TAMPERING AND FRAUD ... A method of detecting session tampering: establishing a Session ID for an online .... to provide solutions against session tampering and/or hijacking. ...
Hack-LU 2005 - Kristof Philipsen - Web Application Vulnerability ... Parameter Tampering in Resource Authorization Systems. } Trust Relationship Issues (MD) .... Use Session ID API functions available in web server: ...
Anti-CSRF and static pages - deep inside | security & tools Talk: Problems and solutions for testing web application security scanners ... In this case you could simply use the session id as in the article of ...
(Microsoft PowerPoint - SYTYKE - nSense - Joakim Sandstr\366m) Failure result: SQL Injection, Parameter Tampering ... MITM attacks. Session Hijacking. Worms? – Myspace? nSense Security Solutions ...
Parosproxy.org - Web Application Security SSL Cipher suite check; Cookie tampering check (CRLF injection); Buffer overflow check; Session ID potential exposure in referer; Session ID locate ...
Imperva Glossary | Session Hijacking In an HTML page, a session ID may be stored as a hidden field: ... using the HTTP referrer header where the ID is stored in the query string parameters, ...
Chris Shiflett: Session Riding The main solution presented (Solution 1) is very similar to the solution I .... For example is XSS a form of parameter tampering, and it's missing input ...




Search This Site:










export multiple gridviews to single excel file

httpwebrequests and httpwebresponse: manipulating webpage controls via code

s.o.s.

installing resources for custom modules through install/language doesn't seem to work

drop down menus and breadcrumbs!

output parameter

creating a new object using reflection

setting up credentials for authentication

uip questions

hmac-md5 encryption problem

signin.ascx : impossibility to loggin

auto-loading multiple content areas in 1 master page

status on module dev docs from the core?

can i use the membership controls with a different schema ?

recordset = nothing

newbie question file upload

how do i determine the user's browser? (particularly firefox)

security issues with web controls

help in programatically generating and displaying menu controls

help! the treeview isn't displaying correct

module that can accept more than 1 type of object?

checkednodes: odd behavior

creating/installing new modules

errors on program start

ad counter customization

set control properties on a master page

text editor picks up background colors..

iframe & css 2.0

places to start

what the bug?

 
All Times Are GMT