Alex Rivera | Logout

How can I better protect my php, jquery, ajax requests from malicious users

Asked 2010-11-16T11:53:38.680
12

I send a lot of data through jquerys getJSON method, an example of a function is

function doSomething(sid){
    if(sid){

    $.getJSON("ajax/ajaxDoSomething.php",{sid:""+sid+""}, function(data){
        //alert(data);
        if(data.success == true){
            $('#add_vote_div').html('vote received');
            $('#list_data_div').html(data.html);
        }
        else{
            $('#add_vote_div').html(data.message);
        }
    });
  } 
}`

The problem is that anyone can look at the source and see that the location of the php file its sending the GET data to, therefore you could just point your browser there and append data to the URL. I do checks on the data to make sure its the right data type, but i dont want users to be able to go to the url at all.

I thought maybe put all the ajax files behind the main document root which would work but jquery can't link to absolute paths like

$.getJSON("var/www/ajax/doSomething.php",{sid:""+sid+""}

(main document root is var/www/html/)

if they made a $.postJSON that would work better, but it doesn't exist, any ideas?

Edit
Report

3 Answers

4

There is no way to secure data with JavaScript. because all the code in the client side code is available to the attacker. You can try to mask the data connection via complex JSON. but every script kiddie can easily use wireshark and view source and see how the data is generated or where it is sent to.

The solution is to use flash to hash the data. Create a small flash file to receive the data, SALT it and encrypt it with MD5. than sent it to the server. the attacker is able to see the data but it is encrypted.

The attacker can still try to de-compile the flash.

answered 2010-11-16T12:06:59.267
3

It only raises the bar to hacking very slightly, but you can POST JSON via jQuery.ajax (that's a link) or jQuery.post (so's that). jQuery.getJSON is just a wrapper for ajax (as are .post, and .get). From the getJSON docs:

This is a shorthand Ajax function, which is equivalent to:

$.ajax({
    url:      url,
    dataType: 'json',
    data:     data,
    success:  callback
});

Thus, to do your postJSON concept, you'd just add a type parameter to it:

$.ajax({
    url:      url,
    type:     'POST',   // <== the new bit
    dataType: 'json',
    data:     data,
    success:  callback
});

If you really wanted to, you could add a postJSON to the jQuery object, pre-processing the arguments and then calling $.ajax. This is basically a copy-and-paste from the jQuery source, but switching .get to .post:

if (!jQuery.postJSON) {
    jQuery.postJSON = function( url, data, callback ) {
        return jQuery.post(url, data, callback, "json");
    };
}

Mind you, it's still pretty easy to fake a POST. Not as easy as a GET, but still pretty easy.

answered 2010-11-16T12:00:20.217
1

to better protect your server from malicious users you need to check the data that come with each request. even if you obfuscate your client code it is always possible to trace where requests are going by using other means. even if you switch to POST requests it is possible to manually create these too.

answered 2010-11-16T12:00:47.170

Your Answer