hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : SSL and Sessions
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

SSL and Sessions

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 03-09-2006, 04:52 PM
jon31 jon31 is offline
Junior Guru
 
Join Date: Jul 2003
Posts: 236
Question

SSL and Sessions


Hey folks,

I'm creating a custom shopping cart, and it's a 3 step (3 page) process. When you go to step 1, the previous page's information is stored in a session. If these forms are being filled out on a SSL page, are the sessions secure, or are they not effected by the certificate?

Please advise.

Jon

__________________
Coding my way to oblivion.

Reply With Quote


Sponsored Links
  #2  
Old 03-10-2006, 08:46 AM
InstaCarma_carmen InstaCarma_carmen is offline
Junior Guru Wannabe
 
Join Date: Mar 2006
Posts: 48
Hi Jon,

Sessions will not be affected by the ssl certificates if you pass them from normal (http) links to secure ssl links (https). But try to browse the pages via https to ensure that all the data is encrypted before processing.

Sincerely,
Carmen [carmen@instacarma.com]

__________________
InstaCarma.com
24x7 Technical Support and Server Management

Reply With Quote
  #3  
Old 03-10-2006, 12:26 PM
jon31 jon31 is offline
Junior Guru
 
Join Date: Jul 2003
Posts: 236
The sessions are only being set and read between https pages, but does that mean that I need to kill the sessions as soon as the order is complete, so that if they do browse to a non-secure page, their session data would be exposed?

__________________
Coding my way to oblivion.

Reply With Quote
Sponsored Links
  #4  
Old 03-10-2006, 07:58 PM
garaget garaget is offline
Newbie
 
Join Date: Jul 2003
Location: California
Posts: 25
Quote:
Originally Posted by jon31
The sessions are only being set and read between https pages, but does that mean that I need to kill the sessions as soon as the order is complete, so that if they do browse to a non-secure page, their session data would be exposed?
From my understanding you should only worry about killing the session variables only if that info is valuable enough to keep off their screen other wise the sessions should time out anyway. I always clear my cart items after checkout so they don't add the same items again but your user info shouldn't really matter so they can keep shopping right?

Reply With Quote
  #5  
Old 03-10-2006, 08:03 PM
jon31 jon31 is offline
Junior Guru
 
Join Date: Jul 2003
Posts: 236
Well I'm sending Credit Card information from one page (Step 2), to another page (Step 3), via a session. Could that be intercepted? Since sessions are just cookies stored on the server, they'd have to hack the server to get the sessions, right?

__________________
Coding my way to oblivion.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
CISO Summit 2013 Web Hosting Events 2013-05-22 13:04:52
Cloud Expo 2013 Web Hosting Events 2013-04-24 17:21:38
Rackspace Offers OpenStack Training Sessions as Part of MIT January Term Web Hosting News 2013-01-15 14:05:08
HostingCon Day 1 Blog 2011-08-08 22:53:21
Your Peers Love HostingCon. Find Out Why & Register for 2011 Blog 2011-06-10 14:10:34


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?