Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Authenticate someone by ip, how safe is it?

Posted on 2004-03-25
2
Medium Priority
?
186 Views
Last Modified: 2010-04-11
Hi I have a script on a web server that is accepting xml from certain ip's that I approve. How easy is it for somone to spoof one of my approved ip's and send me unauthorized data? Is there some way that I can check that they are really sending from that ip?
0
Comment
Question by:jimkat
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 6

Accepted Solution

by:
bloemkool1980 earned 2000 total points
ID: 10685790
if it is only sending and the spoofed IP does not need a response it is pretty easy to do it.
I would rather put authentication before you allow them to send. And no you cannot verify if it is spoofed or not unless it is not going over the internet you could check the mac address.
So unless he needs to click on something as a confirmation before sending it is not safe at all. I would rather suggest putting in authentication in combination with the IP address.
0
 
LVL 18

Expert Comment

by:chicagoan
ID: 10686063
as bloemkool1980 indicated, one can easily spoof an IP address BUT it's a one way street, they can send you packets but never get an answer. TCP/IP requires a three-way handshake to establish a connection, you can't just send a steam of packets as with UDP.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The well known Cerber ransomware continues to spread this summer through spear phishing email campaigns targeting enterprises. Learn how it easily bypasses traditional defenses - and what you can do to protect your data.
IF you are either unfamiliar with rootkits, or want to know more about them, read on ....
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video Micro Tutorial shows how to password-protect PDF files with free software. Many software products can do this, such as Adobe Acrobat (but not Adobe Reader), Nuance PaperPort, and Nuance Power PDF, but they are not free products. This vide…

664 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question