Help needed to encrypt QueryString

I have created a website that utilises query strings to display data as the user navigates among the pages. I would like to encrypt the query string so that the user does not see the actual value of the query string.

I have been searching online for a solution but no success.

Please reply with working code so that i may encrypt all the query strings in my website.

This is the code i am using now to navigate between pages.

Response.Redirect("EditRequest.aspx?RequestID=" + Server.HtmlEncode(GridView1.SelectedDataKey.Value.ToString()));

Thank You.

0
nickoy
5/4/2009 5:18:46 PM
asp.net.security 27051 articles. 1 followers. Follow

4 Replies
1110 Views

Similar Articles

[PageSpeed] 26
Get it on Google Play
Get it on Apple App Store

You can also use Sessions to transfer data as they are secure than querystrings

http://msdn.microsoft.com/en-us/library/ms178581.aspx

and if you want to encrypt querystrings refer here

http://www.devcity.net/PrintArticle.aspx?ArticleID=47

http://www.codeproject.com/KB/web-security/QueryStringEncryptionNET.aspx

http://nayyeri.net/blog/how-to-encrypt-query-string-parameters-in-asp.net/


MAKMark as Answer if this reply helps you
MVP ASP/ASP.Net
MVP ASP/ASP.Net
ASP.Net Hosting : Host DepotMy Site : ASPSnippets
0
mudassarkhan
5/4/2009 6:03:07 PM

You could use a Base64 conversion so you can encrypt/decrypt the querystring values easily (and someone with little knowledge too).

Take a look at the Convert.ToBase64String and Convert.FromBase64String methods to accomplish the task.

Check this link: http://msdn.microsoft.com/en-gb/library/dhx0d524(VS.80).aspx

I wouldn't use this method if I really wanted to hide the information in the querystring.

Hope this helps




If this post is useful to you, please mark it as answer.
0
Hubble
5/4/2009 6:03:39 PM

I have deceided to use a secure query string. The links were helpful. Thank you.

I am however getting an error message on my destionation page that the input string is not in the correct format. Please see below for the code snippets. I am using the query string to access  a users' data in a gridview. Please reply with your suggestion(s).

SourcePage.aspx 

protected
void GridView1_SelectedIndexChanged(object sender, EventArgs e)

{

string encrypt = EncryptClass.encryptQueryString(GridView1.SelectedDataKey.Value.ToString());

Response.Redirect("EditRequest.aspx?RequestID=" + Server.HtmlEncode(encrypt.ToString()));

}

DestinationPage.aspx

protected void Page_Load(object sender, EventArgs e)

{

string decrypt = Request.QueryString["RequestID"];

decrypt = decrypt.Replace(" ", "+");

decrypt = EncryptClass.decryptQueryString(decrypt);

 

}

0
nickoy
5/4/2009 8:43:56 PM

Hi All,

Thank you for your help. I have solved the problem by reading the above and visiting this link. It works.

http://madskristensen.net/post/HttpModule-for-query-string-encryption.aspx

 

0
nickoy
5/4/2009 9:40:59 PM
Reply:

Similar Artilces:

Secured Net Sharing .. Help Needed
There is one Dell Server with 2 NICs. One Nortel Secured Router and Nortel Switches. All I need is 1.) Server Operating System Shud be SuSE 2.) Squid to be configured on that dell server All clients can access net only via proxy no porn sites no adult contents and I even want to add some more websites that are to be restricted. how do i proceed? I wud be really grateful if anyone has enough patience to provide detailed information about various configurations needed... -- tanmaya ------------------------------------------------------------------------ Some ro...

Help needed securing my .NET web application
Hi there!I have a web application that has 3 components:     The VB.NET code to handle the web Requests and calls,    A .NET DLL that handles some vital processing which calls    A VB6 DLL that does some other vital processingI am trying to secure my application so that all the components check to make sure that the calling code has  permission to execute it.I'd like to use CAS Demands to check the stack to make sure all of the code components responsible for the call have permission to do so. My problem is that the VB6 DLL doesn't use the .N...

Need help working around .NET security
I have problems with .NET security blocking the network programs I create.  If I use caspol to give full trust to the internet zone, then everything works fine.  I know I can use the Strong Name utility to create a strong name and add it to all my assemblies, but I would like an easier way.  Is it possible to disable .net security within my program and then re-enable it before closing the program?  I'm the network admin and I run apps that fix problems, or change account passwords, etc.  I have been told that some people will create an application in a non-.net p...

I need help with application security!!! Please Help!!!!
I have been working with webmatrix for a few months now and decided to tackle security.  I've read 2 books and everything that I can find online.  I still can't grasp it.  Can someone please help me with this?Here is the situation:I have a folder called Timesheet.  This folder is the root folder for this application, but it is not the root folder for the domain.  Within the Timesheet folder I have 3 sub-folders: Admin, Advisor & Student.  I also have a logon page that will check username and password against values in a database(SQL Server 2000).  When the user logs in, the logon page should write a cookie that states their account type(m - admin, s - student, a - advisor).  The student should only be able to access the files in the student folder.  The advisor should only have access to the advisor folder.  The admin should have access to all folders.Can someone please help me with the web.config, the process to create the auth cookie and the process to read the cookie and keep the users in the correct folder?Here is the web.config that I have in the domain root:<configuration>    <system.web>        <customErrors mode="Off"/>        <authentication mode="Forms">            <forms name="AuthCookie" loginUrl="/Timesheet/Login.aspx" />   &n...

Help needed with Security !!!!
Hi, I've got a problem with the Security Service using PFC (5.0.3). The of_InitSecurity(..) works well when I'm running my application from within PB, while it returns -2 when I run the .exe. Could anyone explain me why ? Thanks a lot, Enrico. On Fri, 08 May 1998 11:56:27 +0200, Enrico Gentili <e.gentili@sago.fi.it> wrote: >Hi, > I've got a problem with the Security Service using PFC (5.0.3). >The of_InitSecurity(..) works well when I'm running my application from >within PB, while it returns -2 when I run the .exe. > >...

Help Help Help Help Help Help
------=_NextPart_000_0074_01C2960E.EBE13A30 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Can someone please help me. I have installed mysql on Unix Solaris and it works fine I have Perl installed previously which is working and with which i have installed other perlmodules before and are working fine. I have also installed DBI and it works fine with the Sybase drivers which i have installed. When i tried to install the Msql-Mysql-modules-1.2219 drivers i get the following error. # make /usr/local/bin/perl -Iblib/arch -Iblib/lib -I/...

HELP!HELP!HELP!HELP!HELP!HELP!
I was using powerbuilder4.0 a month ago I decided that migrate it to PB7.0 When Im using 4.0, in datawindows I was using extra colums additional to stores procedure. I mean that for example; stored proc. returns 4 columns. I was using 2 extra columns to modify something from client. But I cant do the same thing in PB7.0. How can I do that??? please help. Gurcan yucel gyucel@infina.com.tr "I was using 2 extra columns to modify something from client." what does this mean that you added to the result set? If so then just goto the SQL and add a param. Then set the...

Need help!!! (T.T) please help me......08/07/2007 i need the information....some people help me....
my qeustion is.....  how the ASP.NET allows programmers to use different programming languages in a same project every brother sister.....plesae help me.....i cant do it....cant understand it.......i must get information before 09/07/2007..... please help me....urgent...... Hi, please take a look at this article: Using VB.NET and C# in the same ASP.NET 2.0 project. Grz, Kris.Read my blog. Handy Firefox plugins for web developers.Workaround for non working Mark as answer buttons. hi.....Kris~~ Thanks a lot for ur help xD.... Very happy.....got nice people like you can help m...

Application Error Need Help need help bad!!!!!!!!!
Hi I seem to have a huge problem on my hands.  I launched my website MyDesignerResource.com and used visual web developer to create dynamic pages.  I tried to put those on my webpage but everytime you login etc it gives me an application error.  I cannot figure out how setup the asp.net and sql server express 2005.  I tried everything i converted it to a .sql but i do not know what to put in the strings etc.  Could someone walk me through the steps in doing this.  By the way im using godaddy.com for my webhosting and i have a database setup there i just cant tak...

HELP! Need help with this
Greetings gurus, Get an error while creating this SP with cursor. Can someone please review it and let me know WHERE am I going wrong? Thanks! CREATE PROCEDURE sp_proxy_load as BEGIN declare CT DATE; /* Current time being initialised to a variable */ declare PT DATE; /* Past time being initialised to a variable */ -- Variables for the comments cursor declare xInvPayID int; Declare xLineNum int; declare xdata char(60); declare xAuditActionCD char(1); declare xAuditActionDT DATE; -- variables for the cursor ...

Need help with help
Where do I find where I can set whether SM opens in the current window or a new window. I've looked in Edit Preferences, but must be blind. Jim L via the eCS 1.24 version of OS/2 -- Hi Jim inkleputDEL@ETEisp.com wrote: > Where do I find where I can set whether SM opens in the current window or > a new window. I've looked in Edit Preferences, but must be blind. Close - but no cigar :-) Edit -> Preferences -> Navigator - Tabbed Browsing Regards Pete inkleputDEL@ETEisp.com wrote: > Where do I find where I can set whether SM opens in th...

Help! I need help!
Name: Nathalia Penteado Email: nathpenteadoatuoldotcomdotbr Product: Firefox Summary: Help! I need help! Comments: Hi, I'm a usuary from Firefox for a long time but now i'm having some problems that I can't resolve. All pages that I always stay now can't open. My website don't open in Firefox, and Buzznet, Myspace, all this websites when i'm on. Anything works. Orkut is the same problem. I re-downloaded the firexfox, more than 3 times again, but anything works. I don't know what anything else to do. Thanks for you time Nathalia Penteado Browser Details: Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-BR; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12 ...

Big trouble I need help...help help
Hi everbody I have a problem with a (ACL) password management. After create a Role Organizational. Give security equal at a user. Give trustee at one organization (ex. Alias) on one property (password management) rights to change password. At logon, I use this user who have change password now. Great that work at this organization but i can too reset the password of ADMIN. It's normal ???????????????/ That a bug...$#%#$%$#$%# Thanks you, Chris This is normal. Place an ACL filter on admin to block these rights. There is nothing special about the "Ad...

HELP HELP HELP, the security of my site is in danger!!!!
Ok im desperate!!! ive just built a website, that hase 3 login sections. its for a small company, and its designed for their emloyees. two sections are for the emplyees, and there is a admin section. the authentification is forms.... Now... this is what happend. A sound engineer was doing some contract work, and my boss showed him the website. this guy said. 'whats the password' and my boss said 'none of your business'.. then this guy ran a little script and got into the admin section instantly!!! he was then able to move freely through out the site without any authorisation wha...

i need some help in datawindow.net
i write some code in powerbuilder like this datawindow ldw ldw = dw_1 how can i write the same in C# and please to all the group is there any decument for datawindow.net on C# thank you very much Ramzy Nashaat Ramzy Sybase.DataWindow.DataWindowControl ldw; ldw = dw_1; On 29 Nov 2004 03:47:30 -0800, "Ramzy Nashaat Ramzy" <ramzy.nashaat@connection.com.eg> wrote: >i write some code in powerbuilder like this >datawindow ldw >ldw = dw_1 > >how can i write the same in C# > >and please to all the group >is there any decument fo...

Help needed with here documents (security?)
I'm not actually/formally a Perl "beginner", but this problem is making me feel like one. About a day ago, some schmuck set about to try, hard, to exploit the personally written Perl code I have in place and that processes the input for the contact form on my web site (www.tristatelogic.com). Fortunately, it appears that 99+% of these attempts failed miserably, because I was already well and truly aware of the dangers of processing un-checked input data before I started writing the contact form handler code, several years ago. What worries me is that I have two m...

Help Help Help Help
i need to create a crosstab report using Crystal reprot for VS 2003 i face aproblem when i need to order my Fileds by their names my data must be like this Basic Cola Housing Gross Deduction1 Deduction2 Deduction3 Net but when i run my report it give my a not sorted data acutally i have acode field which can i order field using it. but i don't knwo how to do thisSo..................? Select Report tab | |-->Select Record Sort expert Choost the fields you want to sort --Select the corresponding sort direction f...

Request.Querystring help needed....
Hi all, I am fairly new to asp.net and am doing a University assignment. On one page of my website i have a registration webform for a new user, on click of the 'Register' button it adds the users details to the sql server tblusers table.I then want it to response.redirect to a 'registered' page where it displays welcome then the users firstname, surname, username and password. Which i want to pull back from the initial 'newuser.aspx' page.What is the easiest way to do this, bear in mind i will be passing the users password through and may not want it in clear text.T...

new to .net need help
I am new to .net and am starting to learn it on my own. I have used the VS ..net IDE for generating an extensive MFC code for my Masters Thesis. I am familiar with ASP and VB very much. I have decided to climb the next step by learning .net. I went to http://msdn.microsoft.com/library/default.asp?url=/library/en-us/vsintro7/html/vblrfwalkthroughcreatingrichclientapplicationwithmfc.asp to see some tutorials and this talks about SQL server and the pubs database. Which tells me I need to configure a lot of things before I can start the tutorials can someone point me to the ...

Need help from .NET folks
Dear All, I have been working on the legacy applications from past 5 years and now there is a challenge for me to learn .NET I am not that new to Microsoft technology as I have completed my computer engineering from one of the very good university - Mumbai/India. But since I am totally out of touch on this new technology, rather a new born baby, I would like to know what is the best way to start learning .NET from beginning? I will appreciate if someone can help me guiding through this challenge. Thanks in Advance, new 2 .NET   http://www.asp.net/learn/ And ASP.NET 2...

Urgent QueryString-Need Help!
Dear Sir, I am making a simple aspx form. Once its displayed using in window.open, I call it again by clicking on a link in that page and pass data using query string. The data is passed correctly as i can check from properties of that page but in my page load routine when i try to access any of values of the query string no value is shown. Please help me!. thanks. querystring = test.aspx?myvar=1 Public Sub PageLoad if Not IsPostBack Then Dim myvar As String = Request("myvar") end if end sub Jean-Francois Borie"Jef"...

pfc-security
Hi, I am trying to implement pfc security. None of the users have security defined. All users will belong to one or more groups. Each group has security defined It was my understanding that if a user belongs to more than one group, the group setting with the highest priority is used (0 being the highest priority) I have a user defined in group1 with priority 0 and group 2 with priority 99 When I run the application, the security applied is for group2 with priority 99. Why ?? I have tried debugging/stepping through the code and could not figure out where pfc checks for priority. For dws, pfc will disable the datawindow (tab_seq=0) when the status is <> 'E'. If there were 2 rows (due to 2 groups), it only check for <> 'E'. Am I missing something !! Would appreciate an early response as I need this to work by Friday COB. Please email me directly if possible. <Desperate for a solution> I'm responding from memory here... d_pfcsecurity_controllist is used to retrieve the rights for all controls for the user has a sort order by control then by priority (ascending) on it. It finds the first matching record for that right and uses it. In several locations filters are applied and resorting occurs. You may want to walk through the debugging and verify that the sorting is occurring properly. Regards, John Olson [TeamPS] Developower, Inc -------------------------------------------- (emailed responses are...

Urgent help needed (.NET)
I have a question about .NET. I have created an aspx page with a form, and user control for password which has Textmode set to Password. When I submit the form, the value of Password textbox gets lost and is not captured in viewstate hidden field. I read on some forums that this is a feature of .NET framework. How do I solve this problem. I want to capture the value that I enter for the password field. Please help, Thanks. How do you mean it gets lost and is not captured? what are you doing with the value and are you using script or code behind...Post some code so we can help ...

needed help in securing webservices
hello everyone guys is it possible to secure a webservice i mean a .asmx file alone from users not to see it or to access it  , c guys iam new in this concept where i have to create a webservice for an application and to implement , b4 trying out in huge levels , iam trying some small applications in my local machine , i ve created a small appl like adding , sub, mul of 2 nos using a webservice , i will state the steps i ve done , so it will be easier for everyone to understand 1) i created a test.asmx file in a localproject(nameof the project "webservice") and written the f...

Web resources about - Help needed to encrypt QueryString - asp.net.security

Platform Updates: Operation Developer Love
Since last Wednesday's post , we announced all the events in april we will be attending. Defaulting new apps to sandbox mode Starting today, ...

Oxford Professor of Poetry - Wikipedia, the free encyclopedia
(£4,695 as of 2005) plus £40 in travel expenses for each Creweian Oration . The Professor of Poetry delivers three lectures each year. In addition, ...

Z- blog跨站脚本攻击漏洞 - 80sec
Z- blog跨站脚本攻击漏洞

Check Websites For Bad Links And Invalid References In Mac - Integrity
One thing which should be considered to maintain the integrity of a website is that it must not have too many broken links, as they don't only ...

Smart cache-busting for your WordPress stylesheet
Is this a frustration you're familiar with? If you're like me you mess around with your Wordpress CSS stylesheet fairly ...

Getting Schooled: An America Tonight special series - Al Jazeera America
On air and online, America Tonight explores in depth some of the biggest hurdles keeping kids from a good education

AlloyUI
1.7.0 YUI 3.7.3 APIs Classes Modules Everything A.DataType.DateMath A.HTML5 A.io A.Node A.NodeList A.Plugin.IO Anim App App.Base App.Content ...

Serverside stylesheet switcher
Stylesheet switcher using jQuery This page can be used so that the stylesheet switcher degrades gracefully where Javascript is disabled or the ...

DEA Educational Foundation Gift Shop - Apparel, Office Supplies, Desktop, T-Shirts, Polo Shirts, Hats ...
0 Items My Account - Order Status A Problem Occurred: Invalid input or characters from QueryString. Invalid input or characters from Querystring. ...

What is the limit on QueryString / GET / URL parameters? Finding content
What is the limit on QueryString / GET / URL parameters?

Resources last updated: 3/14/2016 4:19:32 PM