Solved

Cross Site Scripting or Redirects?

Posted on 2012-03-20
3
277 Views
Last Modified: 2012-03-24
Here's my problem:

I have a site that contains sensitive Law Enforcement data.  A few state governments are stepping in and saying that since I am a private company, people cannot share the data they have with me.  We've been doing the same thing for over 10 years and now were running in to problems.  

One of my forms that collect the sensitive data is going to be owned by a government entity,  How can I pull data and insert data in to a sql db that is maintained on a seperate server than my website.  Is it SAFE to do so without compromising all the data?

Can you think of any other way that users can fill in these sensitive forms and it all be handled by the server of the government.  I have full access to both servers so that's not an issue, I'm just wondering what's the most secure and safeset way to send data and get data across two different sites?
0
Comment
Question by:deputycheek
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 110

Accepted Solution

by:
Ray Paseur earned 500 total points
ID: 37744090
With something like this I would write a "web service" to request the data and a complementary web service to send the data.  Put them both behind HTTPS.  You can use a RESTful interface for this.  You can use md5() strings to verify that the messages are complete.
0
 
LVL 36

Expert Comment

by:Loganathan Natarajan
ID: 37745696
Yes, I support for RAY's comment.   We can store all the data into WEB SERVICES  and it can be processed securely with API's (SOAP / REST)
0
 
LVL 110

Expert Comment

by:Ray Paseur
ID: 37747249
Sidebar note...  "Cross Site Scripting" is a term of art that usually describes a security exposure.
https://www.owasp.org/index.php/Cross-site_Scripting_%28XSS%29
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

3 proven steps to speed up Magento powered sites. The article focus is on optimizing time to first byte (TTFB), full page caching and configuring server for optimal performance.
This article discusses how to implement server side field validation and display customized error messages to the client.
Learn how to match and substitute tagged data using PHP regular expressions. Demonstrated on Windows 7, but also applies to other operating systems. Demonstrated technique applies to PHP (all versions) and Firefox, but very similar techniques will w…
The viewer will learn the basics of jQuery including how to code hide show and toggles. Reference your jQuery libraries: (CODE) Include your new external js/jQuery file: (CODE) Write your first lines of code to setup your site for jQuery…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question