Securing a get request using HMAC

6 views
Skip to first unread message

Mike Hogan

unread,
May 12, 2014, 6:26:26 AM5/12/14
to utter...@googlegroups.com
Folks, I have written a general purpose HttpHandler that can check the authenticity of a request using HMAC.  However, it includes the http method and url only in the inputs to the signature (along with the secret key of course).  I am fearful there may be a way to exploit this that I am not aware of (by allowing the request headers to be changes), so I asked on stackoverflow, and am now cross posting here as this list is likely to really understand the issues (right? :) )


Ta,
Mike.

Reply all
Reply to author
Forward
0 new messages