Program Verification login security issues

Source: Internet
Author: User

Security issues related to asp program login verification
 
First read a piece of code
<%
If Request. cookies (CookiesKey) ("xxxxxxadmin") = "" then
Call ERRORMESSAGE ()
Response. End ()
End if
%>
 
This is a piece of login verification code.
 
The error message is displayed if the COOKIE value xxxxxxadmin = is null.
 
Since it is not allowed to be empty, it will be forged, for example: asdf
 
Solution:
If Request. cookies (CookiesKey) ("xxxxxxadmin") = "" then changed to if Request. cookies (CookiesKey) ("xxxxxxadmin") <> password then
 
The password function queries the database.
 
<> Not equal
 
The error message is displayed if xxxxxxadmin is not the same as the password.
 
What if he guessed your MD5 password ?? If he cannot crack it, he will counterfeit the MD5.
 
Solution: Use SESSION Verification
 
The SESSION adds security because the SESSION can only be obtained from the server.
 
Even if hackers get the MD5 value of your password
 
The SESSION is generated unless the other servers are noticed.
 

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.