?
Solved

Security in Query String Variables

Posted on 2012-04-02
5
Medium Priority
?
348 Views
Last Modified: 2012-04-06
Environment: C#.NET 4.0, Webforms

I need to place a primary key variable in a query string and would like to do it securely (e.g. prevent semantic URL attacks, etc.)  I am fairly new to ASP.NET and was wondering what these best technique, or techniques, are to accomplish this.

Any thoughts on the most secure techniques and those techniques that are part of "best practices" would be appreciated.
0
Comment
Question by:adskarcox
5 Comments
 

Author Comment

by:adskarcox
ID: 37796726
Here is an example of what I need to do:

http://www.myapp.com/ViewProduct.aspx?id=1234

I need to do this securely.
0
 

Author Comment

by:adskarcox
ID: 37796736
I was considering using a guid in the query string, instead of the row's primary key, but I have read that placing a guid in the query string is bad form.
0
 
LVL 14

Assisted Solution

by:binaryevo
binaryevo earned 334 total points
ID: 37797103
Yes, deffiantely a security risk either GUID or the ID.  I would Encrypt it with an AES encryption library or write your own.  .Net has many different ways to utilize encryption technology.
0
 
LVL 19

Assisted Solution

by:Manoj Patil
Manoj Patil earned 332 total points
ID: 37797846
Hi you can Encrypt the QueryString like following

http://www.codeproject.com/Articles/25719/Query-string-encryption-for-ASP-NET
0
 
LVL 8

Accepted Solution

by:
cubaman_24 earned 334 total points
ID: 37799833
Hello:
I would check users rights in server side code instead of spend time hiding the real id.  It would be more secure and less time consuming.
0

Featured Post

Get your problem seen by more experts

Be seen. Boost your question’s priority for more expert views and faster solutions

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

The article shows the basic steps of integrating an HTML theme template into an ASP.NET MVC project
There is a wide range of advantages associated with the use of ASP.NET. This is why this programming framework is used to create excellent enterprise-class websites, technologies, and web applications.
Hi, this video explains a free download that you can incorporate into your Access databases, or use stand-alone for contact management. Contacts -- Names, Addresses, Phone Numbers, eMail Addresses, Websites, Lists, Projects, Notes, Attachments…
Watch the video of Kernel Migrator for SharePoint, which demonstrate the process easily of migration from SharePoint to SharePoint, OneDrive for Business & Google Drive servers, Public Folder to SharePoint, File Server to SharePoint. The tool has va…

590 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question