Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old January 29th, 2006, 09:21 PM
DantePonz DantePonz is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2005
Posts: 60 DantePonz User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 23 h 20 m 30 sec
Reputation Power: 4
Application to Internet - Grabbing/Sniffing Question

Is it possible to grab/sniff communications between a local application and a server? We have an application in development which resides locally but gets all of its data from php/mysql scripts. Some of the material is sensitive. Should my application call http:// or https:// pages? Is the SSL concern only present in browser-server interactions?

Reply With Quote
  #2  
Old January 29th, 2006, 10:37 PM
kuza55's Avatar
kuza55 kuza55 is offline
It's only wrong if you're caught....
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: Dec 2003
Location: Sydney, Australia
Posts: 1,286 kuza55 User rank is Second Lieutenant (5000 - 10000 Reputation Level)kuza55 User rank is Second Lieutenant (5000 - 10000 Reputation Level)kuza55 User rank is Second Lieutenant (5000 - 10000 Reputation Level)kuza55 User rank is Second Lieutenant (5000 - 10000 Reputation Level)kuza55 User rank is Second Lieutenant (5000 - 10000 Reputation Level)kuza55 User rank is Second Lieutenant (5000 - 10000 Reputation Level)kuza55 User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 3 Weeks 3 Days 6 h 10 m 16 sec
Reputation Power: 97
Quote:
Originally Posted by DantePonz
Is it possible to grab/sniff communications between a local application and a server? We have an application in development which resides locally but gets all of its data from php/mysql scripts. Some of the material is sensitive. Should my application call http:// or https:// pages? Is the SSL concern only present in browser-server interactions?

Firstly, yes it is possible to sniff data between an application and a server, but it depends on the setup. e.g. if every computer which is going to connect to your server for data is connected directly to the router via a cable (i.e. not wifi), then the chance of people being able to sniff the traffic on the local side are very limited. if on the other hand you anticipate people trying to access the data from unsecured wifi networks, then things are definitely sniffable. It all depends on the setup, primarily on the user end, since most attackers will not have access to your server's LAN, right? And there is almost zero chance that an attacker has access to your ISP, or any of tier 1 ISPs through which traffic is going to get routed.

If you're sending sensitive data then encryption is a good idea. Whether you do that via SSL or something else depends on your situation. The only vulnerability (that I know of, correct me if I'm wrong) that exists in SSL is that it like all asymmetric encryption schemes (and SSL uses asymmetric key cryptography to negotiate a key for the symmetric encryption which is used for the length of the connection) it is vulnerable to Man in the Middle (MITM) attacks, where the attacker intercepts communication between the server and client (ARP cache poisoning is a possibility to cause MITM attacks).

So unless you foresee someone being able to execute MITM attacks on the client end, then SSL is a good way to send your data.

But if you do use SSL your traffic will _not_ be vulnerable to passive attacks such as sniffing.
__________________
- Alex
Web Security Research (my blog)
Handbook of Applied Cryptography (Free!)

Reply With Quote
  #3  
Old January 29th, 2006, 10:48 PM
DantePonz DantePonz is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2005
Posts: 60 DantePonz User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 23 h 20 m 30 sec
Reputation Power: 4
Thanks a ton!

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Application to Internet - Grabbing/Sniffing Question


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT