Re: Hacker problem
| From: | Leif K-Brooks | Date: | Wed, 12 Mar 2003 13:37:12 +0000 |
| Subject: | Re: Hacker problem | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-139282@lists.php.net to get a copy of this message | ||
You're checking with javascript, correct? If so, try checking server-side too.
Pag wrote:
-- The above message is encrypted with double rot13 encoding. Any unauthorized attempt to decrypt it will be prosecuted to the full extent of the law.Been having some hacker problems on my site, and a simple one:I have a shoutbox, a simple form with name and text that adds lines to the database. I do checks for insults, too long words, tags, etc, but its still possible to circumvent those checks by adding the data on the url instead of using the form. something like:www.domain.com/shoutb.php?name=hacker&text=generalnonsenseandbadwordsTo prevent this, i tried tracing the http_referral so that only data from inside the site goes into the shoutbox. THe problem is that if you do that url above after visiting my site, the http_referral obviously thinks its coming from inside the site. :-P How can i solve this? Is there any way to prevent data adding from outside? Maybe some invisible check on the form or something?Thanks.Pag