Solved

Website Login to secure confidential information

Posted on 2008-10-10
8
362 Views
Last Modified: 2013-11-19
We are in the process of setting up a website. On the website we want a secure login link, so our clients can login by screen name and password to access their information.

Each client will need to login with a unique screen name and password, giving them the ability to see the status of their accounts, (i.e. database or spreadsheet of pertinent information, along with ability to upload and download confidential documents, and communicate by posting messages). Due to the type of private information it will need to be encrypted and secured in a way that complies with current information security laws

I was in the process of setting up a website on GoDaddys WebSiteTonight, but it looks like we wont have the ability to set it up the way we need it.

I am unsure as to how to set this up and where to go from here.
0
Comment
Question by:nashvilletn
  • 5
  • 2
8 Comments
 

Author Comment

by:nashvilletn
ID: 22691114
Anyone have an answer???
0
 

Author Comment

by:nashvilletn
ID: 22691117
Anyone have an answer???
0
 
LVL 70

Accepted Solution

by:
Jason C. Levine earned 250 total points
ID: 22691525
Hi nashvilletn,

If you have access to PHP and MySQL: http://www.phpeasystep.com/workshopview.php?id=6

0
Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

 

Author Comment

by:nashvilletn
ID: 22692075
can this be done on godaddy's website tonight?
0
 
LVL 3

Expert Comment

by:wktang83
ID: 22692597
This tutorial (http://www.phpeasystep.com/workshopview.php?id=6) DOES NOT protect you against session hijacking. Unless you're encrypting the connection using SSL, the transmission of data between the client's computer and the server can be intercepted by an attacker, and can be used to hijack the session, and therefore gaining access to the administrative system.

If you are using php, read more about preventing session hijacking here:
http://phpsec.org/projects/guide/4.html

I have written a class in php which is able to defend against session hijacking. If you're interested, post back.
0
 

Author Comment

by:nashvilletn
ID: 22692626
So as long as SSL is utilized will this type of setup work? Do you know if this can be implemented in a website tonight website?
0
 
LVL 3

Assisted Solution

by:wktang83
wktang83 earned 250 total points
ID: 22692655
nashvilletn:

According to this site,
https://www.godaddy.com/gdshop/hosting/hosting_build_website.asp?app_hdr=

they do give you a free SSL cert. (Only for the Premium Plan though).

If you're not on the premium plan, you can have SSL cert as an add-on for $29.99/yr.
https://www.godaddy.com/gdshop/ssl/ssl.asp

SSL certs will enable your website to have secure SSL encrypted connection.
0
 

Author Closing Comment

by:nashvilletn
ID: 31505133
Thank you for your assistance.  It is greatly appreciated!!!
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
FAQ pages provide a simple way for you to supply and for customers to find answers to the most common questions about your company. Here are six reasons why your company website should have a FAQ page
Any person in technology especially those working for big companies should at least know about the basics of web accessibility. Believe it or not there are even laws in place that require businesses to provide such means for the disabled and aging p…
The is a quite short video tutorial. In this video, I'm going to show you how to create self-host WordPress blog with free hosting service.

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question