Solved

Security in Query String Variables

Posted on 2012-04-02
5
322 Views
Last Modified: 2012-04-06
Environment: C#.NET 4.0, Webforms

I need to place a primary key variable in a query string and would like to do it securely (e.g. prevent semantic URL attacks, etc.)  I am fairly new to ASP.NET and was wondering what these best technique, or techniques, are to accomplish this.

Any thoughts on the most secure techniques and those techniques that are part of "best practices" would be appreciated.
0
Comment
Question by:adskarcox
5 Comments
 

Author Comment

by:adskarcox
ID: 37796726
Here is an example of what I need to do:

http://www.myapp.com/ViewProduct.aspx?id=1234

I need to do this securely.
0
 

Author Comment

by:adskarcox
ID: 37796736
I was considering using a guid in the query string, instead of the row's primary key, but I have read that placing a guid in the query string is bad form.
0
 
LVL 14

Assisted Solution

by:binaryevo
binaryevo earned 167 total points
ID: 37797103
Yes, deffiantely a security risk either GUID or the ID.  I would Encrypt it with an AES encryption library or write your own.  .Net has many different ways to utilize encryption technology.
0
 
LVL 19

Assisted Solution

by:Manoj Patil
Manoj Patil earned 166 total points
ID: 37797846
Hi you can Encrypt the QueryString like following

http://www.codeproject.com/Articles/25719/Query-string-encryption-for-ASP-NET
0
 
LVL 8

Accepted Solution

by:
cubaman_24 earned 167 total points
ID: 37799833
Hello:
I would check users rights in server side code instead of spend time hiding the real id.  It would be more secure and less time consuming.
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wouldn’t it be nice if you could test whether an element is contained in an array by using a Contains method just like the one available on List objects? Wouldn’t it be good if you could write code like this? (CODE) In .NET 3.5, this is possible…
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question