http referer: guaranteeing that my $variable's content is my content...
| From: | callen | Date: | Thu, 08 Jun 2000 22:13:52 +0000 |
| Subject: | http referer: guaranteeing that my $variable's content is my content... | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-1342@lists.php.net to get a copy of this message | ||
Greetings To All:
Opinions needed:
Understand that $mustbe is being passed via the URL (ex
http://...com./?mustbe=$mustbe ...)
How insecure/secure is seting a variable on one page ($mustbe=1) to goto
another page
and then checking to make sure on the other page that both $mustbe is 1
and that $HTTP_REFER
is set also?
The data that could be messed with is trivial but still I would rather
have it not be accessible to the unwanted.
Can both of these vars be easily spoofed? Am I correct in assuming that
my whole host(or DNS) would need to be spoofed in order for the
HTTP_REFER to be corrupt? If so, any way around this besides querys to
DB's and cookies?
<SYS:apache,php3,mysql,qmail>
--
Christopher C.M. Allen
Design Inter/Intra Net
Email: callen@driver8.org
Cell : 1.715.821.4006
Home Phone: 1.715.426.6661