http referer: guaranteeing that my $variable's content is my content...

From: Date: Thu, 08 Jun 2000 22:13:52 +0000
Subject: http referer: guaranteeing that my $variable's content is my content...
Groups: php.general 
Request: Send a blank email to php-general+get-1342@lists.php.net to get a copy of this message
Greetings To All: Opinions needed: Understand that $mustbe is being passed via the URL (ex http://...com./?mustbe=$mustbe ...) How insecure/secure is seting a variable on one page ($mustbe=1) to goto another page and then checking to make sure on the other page that both $mustbe is 1 and that $HTTP_REFER is set also? The data that could be messed with is trivial but still I would rather have it not be accessible to the unwanted. Can both of these vars be easily spoofed? Am I correct in assuming that my whole host(or DNS) would need to be spoofed in order for the HTTP_REFER to be corrupt? If so, any way around this besides querys to DB's and cookies? <SYS:apache,php3,mysql,qmail> -- Christopher C.M. Allen Design Inter/Intra Net Email: callen@driver8.org Cell : 1.715.821.4006 Home Phone: 1.715.426.6661

« previous php.general (#1342) next »