Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - HTTP API Security
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

HTTP API Security

 Post Reply Post Reply
Author
DanP View Drop Down
Newbie
Newbie


Joined: 08 May 2012
Location: United Kingdom
Status: Offline
Points: 6
Post Options Post Options   Thanks (0) Thanks(0)   Quote DanP Quote  Post ReplyReply Direct Link To This Post Topic: HTTP API Security
    Posted: 12 November 2012 at 1:57pm
Hi, I'm after a bit of basic information around the HTTP API, more to the point around security around it.   What does it have in terms of security?   Is there anything in it to stop a Brute Force, Dictionary or DDOS attack?   I'm concerned that given enough time and basic scripting someone could obtain the master Admin password and then access to everything within a forum.   Is there something I've missed in the documentation for this API?

Cheers,

Dan
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 12 November 2012 at 2:08pm
The HTTP XML API requires that you pass across the admin username and password in order for the API to validate and run the API call.

If you are worried about security you could install an SSL certificate on your website and then use HTTPS to access the API.

If you are also concerned about Brute Force, Dictionary or DDOS attack then you could look at installing Microsoft's IIS Dynamic IP Restrictions that can block these types of attacks.

Attempting to prevent DDoS attacks at application level within Web Wiz Forums would be pointless as any calls to the application require database hits and so you would not be able to sufficiently stop DDoS at this level. It would be much better using Microsoft's IIS Dynamic IP Restrictions or better still using a hardware firewall, or some Switches from companies like Cisco also have this ability built in.
Back to Top
DanP View Drop Down
Newbie
Newbie


Joined: 08 May 2012
Location: United Kingdom
Status: Offline
Points: 6
Post Options Post Options   Thanks (0) Thanks(0)   Quote DanP Quote  Post ReplyReply Direct Link To This Post Posted: 12 November 2012 at 2:52pm

Hi Bruce, thanks for the quick reply.   I'm happy with the concept that the calls are all encrypted by SSL, it was the repeat attack I was more concerned with.   As you say that can (and probably should) be catered for at hardware or OS level.   Thanks for confirming.

 
Dan
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.