Solved

Security in Query String Variables

Posted on 2012-04-02
5
318 Views
Last Modified: 2012-04-06
Environment: C#.NET 4.0, Webforms

I need to place a primary key variable in a query string and would like to do it securely (e.g. prevent semantic URL attacks, etc.)  I am fairly new to ASP.NET and was wondering what these best technique, or techniques, are to accomplish this.

Any thoughts on the most secure techniques and those techniques that are part of "best practices" would be appreciated.
0
Comment
Question by:adskarcox
5 Comments
 

Author Comment

by:adskarcox
ID: 37796726
Here is an example of what I need to do:

http://www.myapp.com/ViewProduct.aspx?id=1234

I need to do this securely.
0
 

Author Comment

by:adskarcox
ID: 37796736
I was considering using a guid in the query string, instead of the row's primary key, but I have read that placing a guid in the query string is bad form.
0
 
LVL 14

Assisted Solution

by:binaryevo
binaryevo earned 167 total points
ID: 37797103
Yes, deffiantely a security risk either GUID or the ID.  I would Encrypt it with an AES encryption library or write your own.  .Net has many different ways to utilize encryption technology.
0
 
LVL 19

Assisted Solution

by:Manoj Patil
Manoj Patil earned 166 total points
ID: 37797846
Hi you can Encrypt the QueryString like following

http://www.codeproject.com/Articles/25719/Query-string-encryption-for-ASP-NET
0
 
LVL 8

Accepted Solution

by:
cubaman_24 earned 167 total points
ID: 37799833
Hello:
I would check users rights in server side code instead of spend time hiding the real id.  It would be more secure and less time consuming.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

More often than not, we developers are confronted with a need: a need to make some kind of magic happen via code. Whether it is for a client, for the boss, or for our own personal projects, the need must be satisfied. Most of the time, the Framework…
Calculating holidays and working days is a function that is often needed yet it is not one found within the Framework. This article presents one approach to building a working-day calculator for use in .NET.
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now