I may be paranoid  (actually - I would only be paranoid if people aren't 
actually trying to break into my machine...  I am watching my Blackice 
Defender graph now - I had 1,500 attacks in the last 90 minutes:), but when 
i do things like this, I would pass 2 UUIDs through the URL...  one is the 
index into the temporary table, the other is a check - which is also stored 
in the temporary table.  On the second page, I first check that the 2 UUIDs 
match each other before displaying the data...
otherwise, a hacker could set up a loop to take your UUID, and just 
increment it and keep trying until it finds something.  By using 2 UUIDs, 
that would be impractical.

Al Musella, DPM




At 07:56 PM 8/17/2001 -0400, you wrote:

> > A simple solution to this URL truncation problem may be to create a
> > table in your database to use a storage repository for the WDDX packet,
> > insert the WDDX packet into the db, and then just pass a UUID through
> > the URL variable, retrieve the wddx packet from the db, and then
> > recreate your structure.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/[email protected]/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists

Reply via email to