Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


How to encode QueryString in ASP.NET 2.0 and decode in JSP?

Posted on 2006-05-03
Medium Priority
Last Modified: 2008-01-09
After migrating to a ASP.NET 2.0 application I have to add a link to a legacy application written in Java.  Basically my app will use redirect to a login page with http://localsite/login.jsp?name=John&pwd=Hello.  I do not want to display credentials as clear text, what should be done in order to encrypt querystring in ASP.NET 2.0 and then deciphered on JSP page?
Question by:TornadoV
LVL 42

Expert Comment

ID: 16600280
Querystring is going to be visible whether you encode it or not so I'm not sure what you're asking?  You can encrypt 'John' to be 'H&y4Fv_9' but that isn't going to stop someone from copying 'H&y4Fv_9' and pasting it into a URL at a later date...

If you want to have credentials hidden then don't put them in the querystring!
LVL 14

Accepted Solution

Ramuncikas earned 200 total points
ID: 16600336
1. Construct a string containing a user name and password.
     Dim str as string="user=John&pwd=Hello"

2. Encrypt this string with some string encription.

3. Pass the resulting string to java app
     Response.redirect("http://localsite/login.jsp?user=" & MyEcryptedString)

4. Decrypt that string at java app side, parse it into user name and password and check if credentials are valid...
LVL 11

Author Comment

ID: 16614841
Frodoman, I'm sorry for not being clear, it's an intranet app, I simply did not want to display user's credentials as clear text in their address bar.  I was looking for Convert.ToBase64String() equivalent in Java since I'm not proficient in it.  

I gave all points to Ramuncikas simply because I've implemented his suggestion even without looking at it first.

Thanks for your help guys!

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Problem Hi all,    While many today have fast Internet connection, there are many still who do not, or are connecting through devices with a slower connect, so light web pages and fast load times are still popular.    If your ASP.NET page …
International Data Corporation (IDC) prognosticates that before the current the year gets over disbursing on IT framework products to be sent in cloud environs will be $37.1B.
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
With just a little bit of  SQL and VBA, many doors open to cool things like synchronize a list box to display data relevant to other information on a form.  If you have never written code or looked at an SQL statement before, no problem! ...  give i…
Suggested Courses
Course of the Month13 days, 5 hours left to enroll

579 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question