Solved

authenticating a REST call when there is already a session

Posted on 2013-11-13
8
345 Views
Last Modified: 2013-11-14
Hi Experts,

I'm interested in hearing my options when I have a REST API that any authenticated individual can call.  Basically, there's an ID that's reused across multiple REST calls and anyone looking at the URL can do injection attacks on it (if they are authenticated of course).

Any options or best-practices that exist for this?

Many thanks,
Mike
0
Comment
Question by:thready
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
8 Comments
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 39646336
I'm not sure I understand the question.  Anyone who authenticates looks like a legitimate user.  Besides the normal user logouts and session timeouts, what are you looking for?
0
 
LVL 1

Author Comment

by:thready
ID: 39646655
The unique ID used in the REST call is one used during that session, assigned by the server with a previous get from the client.  The rest API can be tampered with if someone sniffs URLs coming from a legitimate user (from another badly behaving legitimate user who's logged in.)  Since anyone can see that unique ID, another user can make a REST call with it with bad data and it would break the behavior of the API...  please let be know if this is still not so clear...
Thanks!
Mike
0
 
LVL 1

Author Comment

by:thready
ID: 39646661
Basically, URLs are not encrypted over HTTPS, so anyone can see that ID.  presumably, all you would need to do to break this REST API would be to use it maliciously...  by logging in and using someone else's ID...  from their own API call...
0
Secure Your WordPress Site: 5 Essential Approaches

WordPress is the web's most popular CMS, but its dominance also makes it a target for attackers. Our eBook will show you how to:

Prevent costly exploits of core and plugin vulnerabilities
Repel automated attacks
Lock down your dashboard, secure your code, and protect your users

 
LVL 83

Accepted Solution

by:
Dave Baldwin earned 500 total points
ID: 39647091
You can not distinguish two users who use legitimate logins.

http://en.wikipedia.org/wiki/Representational_state_transfer

This RFC http://tools.ietf.org/html/rfc2818 says that only the server name is sent in the clear to make a TLS connection and that everything else including the actual URL and headers are sent encrypted.
0
 
LVL 1

Author Comment

by:thready
ID: 39647336
Where does the rfc say that only the server name is sent in the clear? I can't find that anywhere...
0
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 39648782
Note "a connection to the server".
2.1. Connection Initiation


   The agent acting as the HTTP client should also act as the TLS
   client.  It should initiate a connection to the server on the
   appropriate port and then send the TLS ClientHello to begin the TLS
   handshake. When the TLS handshake has finished. The client may then
   initiate the first HTTP request.  All HTTP data MUST be sent as TLS
   "application data".  Normal HTTP behavior, including retained
   connections should be followed.
That is also what I see in Fiddler.
0
 
LVL 1

Author Closing Comment

by:thready
ID: 39649093
Kick-ass answer.  Thanks a lot!  awesome.
0
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 39649178
You're welcome, thanks for the points.
0

Featured Post

Report: Liquid Web beats Amazon, Rackspace & More

A study by performance analyst firm Cloud Spectator finds that Liquid Web beats rivals Amazon, Rackspace and DigitalOcean when it comes to website and cloud application performance.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
PHP Sort Order 5 106
Video and audio capture on Windows 7 3 125
Data Integration Between Oracle DB and Dynamics CRM 2016 5 116
pagenation logic how it is working in my code 1 80
New Relic: Our company recently started researching several products to figure out what were the best ways for us to increase our web page speed and to quickly identify performance problems that we may be having. One of the products we evaluated wa…
New Relic recently released its Synthetics product that allows for the creation of performance monitors that periodically test a site's performance. If you wish to test an interactive workflow New Relic employs Selenium WebDriverJS to run those test…
This video teaches users how to migrate an existing Wordpress website to a new domain.
Learn how to set-up custom confirmation messages to users who complete your Wufoo form. Include inputs from fields in your form, webpage redirects, and more with Wufoo’s confirmation options.

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question