Hacker problem

From: Date: Wed, 12 Mar 2003 13:34:57 +0000
Subject: Hacker problem
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-139279@lists.php.net to get a copy of this message
Been having some hacker problems on my site, and a simple one: I have a shoutbox, a simple form with name and text that adds lines to the database. I do checks for insults, too long words, tags, etc, but its still possible to circumvent those checks by adding the data on the url instead of using the form. something like: www.domain.com/shoutb.php?name=hacker&text=generalnonsenseandbadwords To prevent this, i tried tracing the http_referral so that only data from inside the site goes into the shoutbox. THe problem is that if you do that url above after visiting my site, the http_referral obviously thinks its coming from inside the site. :-P How can i solve this? Is there any way to prevent data adding from outside? Maybe some invisible check on the form or something? Thanks. Pag

« previous php.general (#139279) next »