ASP Programming
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsProgramming Languages - MoreASP Programming

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stay one step ahead of the competition. Evaluate and give feedback on some of the hottest web development tools on the market today. Make your opinion heard! Click Here
  #1  
Old August 19th, 2003, 07:36 AM
bobroq bobroq is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Posts: 3 bobroq User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Curious about the secuirty user login

I have read many (if not all) of the articles listed in this forum in reguards to having a user login on my website. It is necessary for me to have multiple users with differing access levels, as a result of this, I have decided to implement a user login that accesses a mysql database.

In the database I maintain four things about every user: the user id number, user name, access level, and password. I have a simple form that asks the user for their user name and password. I then ask the database to return all users that have the same username and password that as those that were entered in the form. (user names are unique, I assign them myself) If the username and password are found in the database I assign 3 different session variables ( userIDnumber, username, and accesslevel ) and redirect the user to the members only section.

On each members only page I check to make sure the session variables are set and the accesslevel is high enough to view the page.

I was just curious if there were any major security issues in doing this. IE is it possible for someone to artificially set session variables or if there are any major flaws in my way of approaching this etc.

If it will help I can include my code

Thank you for any help
bobroq...

Reply With Quote
  #2  
Old August 19th, 2003, 07:46 AM
Vlince Vlince is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2003
Location: Canada, Quebec, Montreal
Posts: 410 Vlince User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 5
Session variables and/or application variables are a pretty secure way to do things, the only disadvantage is the length of the session variable, for example, that defaults to 20 minutes(Unless you change that setting on your own)

But then again, the best way to protect your data is to NOT MAKE IT ACCESSIBLE VIA INTERNET.

That is the best approach ever...

Now, how *safe* this data of yours must be? I mean are you working for NASA?

Don't get me wrong here, I'm not making fun of you its just that people have the tendency to freak out like if hackers, for some reason, will attack their web sites...Trust me, they have, the good ones, better things to do...

Anyway, Session variable are reliable for the type of security you're trying to implement

That's my own 2 cents

Hope this helps!
Sincerely

Vlince

Reply With Quote
  #3  
Old August 19th, 2003, 09:03 AM
aspman aspman is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Location: Ashburn,VA
Posts: 105 aspman User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 22 m 40 sec
Reputation Power: 5
I couldnot agree more with vLince.

You can certainly use session variables for what you are trying to do.

Reply With Quote
  #4  
Old August 19th, 2003, 10:33 AM
bobroq bobroq is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Posts: 3 bobroq User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Thank you very much for your help.
My information does not have to be NASA level secure :-), but it would be nice to know it is somewhat safe. Basically my company has a privacy policy with our customers in so much that we will not allow one customer to know who another customer is. Don't ask me why we have this policy I'm an admin for a grinding shop.

Once again thank you for your help
bobroq

Reply With Quote
Reply

Viewing: Dev Shed ForumsProgramming Languages - MoreASP Programming > Curious about the secuirty user login


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

 Free IT White Papers!
 
Accelerating Trading Partner Performance
One in five. That's how many partner transactions have at least one error. That is an amazing statistic, particularly given the extraordinary leaps in innovation across the global supply chain during the past two decades. Download this white paper to learn more.

 
Competing on Analytics
This Tech Analysis is designed to help identify characteristics shared by analytics competitors, and includes information about 32 organizations that have made a commitment to quantitative, fact-based analysis.

 
Cost Effective Scaling with Virtualization and Coyote Point Systems
An overview of the industry trend toward virtualization, how server consolidation has increased the importance of application uptime and the steps being taken to integrate load balancing technology with virtualized servers.

 
Five Checkpoints to Implementing IP Telephony
Implementation planning for IP PBX software and IP telephony has become vital as businesses replace discontinued legacy PBX phone systems. This informative whitepaper outlines five "checkpoints" for any implementation plan that will help make IP communications a successful proposition.

 
Hosted Email Security: Staying Ahead of New Threats
In the last two years, email has become a fierce battleground between the nefarious forces of spam and malware, and the heroes of messaging protection. The spam volumes increased alarmingly every month, bringing clever new forms of phishing and virus propagation attacks.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway