Sunday, December 29, 2013

Dealing With Malicious Users

I am working on a fairly large application and I am modify form fields, trying to edit other people's records or just stuff you should not be doing to test things out.

 

My question is how to handle these requests.

Obviously what they are doing gets stopped but do you alert them with a message Illegal Attempt? Log them out? Ban them? Record the error for admin to review and decide later what to do.

Simply dis-regard and do nothing and just a message saying error please try again?

 

If someone is up to no good what is the best way to deal with this? How do you handle it? What do you do?

 

Thanks for any and all insight you guys can provide.

 

Dave

 

 

No comments: