OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Paul Matheu (pmatheu_at_bittime.com)
Date: Wed Jul 10 2002 - 16:00:19 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    You also can encrypt and encode parameters, pass them along, and then decode
    and encrypt them at the other end.

    > ----- Original Message -----
    > From: "Steven Fling" <SFLINGoppenheimerfunds.com>
    > To: <webappsecsecurityfocus.com>
    > Sent: Wednesday, July 10, 2002 2:36 PM
    > Subject: Best Practices for passing data via HTTP
    >
    >
    > Our application communicates across various application
    > server environments
    > via HTTP/HTTPS requests (versus RMI, etc.) and needs to pass
    > data/parameters
    > back and forth. Naturally we use SSL to encrypt the request/response.
    >
    > I wanted to see if there were any Best Practices established
    > to transfer
    > data in this fashion. POST vs. GET method, querystring vs.
    > hidden form
    > variable, etc.
    >
    > Any insight would be appreciated!
    >
    > ____________________________________
    > Steve Fling
    > Managing Architect - Web Development
    > OppenheimerFunds, Inc.
    > sflingoppenheimerfunds.com
    > Office: 303.768.3200
    > FAX: 303.768.1096
    > http://www.oppenheimerfunds.com
    > ____________________________________
    >
    >
    > This electronic mail transmission may contain confidential
    > information and
    > is intended only for the person(s) named. Any use, copying
    > or disclosure by
    > any other person is strictly prohibited. If you have received this
    > transmission in error, please notify the sender via e-mail.
    >
    >
    >
    >