I may be paranoid (actually - I would only be paranoid if people aren't
actually trying to break into my machine... I am watching my Blackice
Defender graph now - I had 1,500 attacks in the last 90 minutes:), but when
i do things like this, I would pass 2 UUIDs through the URL... one is the
index into the temporary table, the other is a check - which is also stored
in the temporary table. On the second page, I first check that the 2 UUIDs
match each other before displaying the data...
otherwise, a hacker could set up a loop to take your UUID, and just
increment it and keep trying until it finds something. By using 2 UUIDs,
that would be impractical.
Al Musella, DPM
At 07:56 PM 8/17/2001 -0400, you wrote:
> > A simple solution to this URL truncation problem may be to create a
> > table in your database to use a storage repository for the WDDX packet,
> > insert the WDDX packet into the db, and then just pass a UUID through
> > the URL variable, retrieve the wddx packet from the db, and then
> > recreate your structure.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Structure your ColdFusion code with Fusebox. Get the official book at
http://www.fusionauthority.com/bkinfo.cfm
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/[email protected]/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists