Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Authenticate someone by ip, how safe is it?

Posted on 2004-03-25
2
Medium Priority
?
188 Views
Last Modified: 2010-04-11
Hi I have a script on a web server that is accepting xml from certain ip's that I approve. How easy is it for somone to spoof one of my approved ip's and send me unauthorized data? Is there some way that I can check that they are really sending from that ip?
0
Comment
Question by:jimkat
2 Comments
 
LVL 6

Accepted Solution

by:
bloemkool1980 earned 2000 total points
ID: 10685790
if it is only sending and the spoofed IP does not need a response it is pretty easy to do it.
I would rather put authentication before you allow them to send. And no you cannot verify if it is spoofed or not unless it is not going over the internet you could check the mac address.
So unless he needs to click on something as a confirmation before sending it is not safe at all. I would rather suggest putting in authentication in combination with the IP address.
0
 
LVL 18

Expert Comment

by:chicagoan
ID: 10686063
as bloemkool1980 indicated, one can easily spoof an IP address BUT it's a one way street, they can send you packets but never get an answer. TCP/IP requires a three-way handshake to establish a connection, you can't just send a steam of packets as with UDP.
0

Featured Post

Ready for your healthcare security check-up?

In the past few years, healthcare organizations have become a prime target for advanced attacks. Does your organization have what it needs to defend itself? Schedule your healthcare security check-up today and download our free Healthcare Security Resource Kit today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are like me and like multiple layers of protection, read on!
It’s a season to be thankful, and we’re thankful for users like you who engage on site, solve technology problems, and network with others in the industry. What tech are we most thankful for? Keep reading.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question