Re: Hacker problem
| From: | Leif K-Brooks | Date: | Wed, 12 Mar 2003 14:03:43 +0000 |
| Subject: | Re: Hacker problem | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-139299@lists.php.net to get a copy of this message | ||
That's just not possible.
Sysadmin@saginawcontrol.com wrote:
Swear filtering is easy, I want to know how to make sure the data is coming from MY form....I'm just picky like that. :-) -----Original Message----- From: Adam Voigt [mailto:adam@cryptocomm.com] Sent: Wednesday, March 12, 2003 8:55 AM To: Sysadmin@saginawcontrol.com Cc: php-general@lists.php.net Subject: RE: [PHP] Hacker problem Why don't you just do the swear filtering on shoutb.php, or wherever it's actually being inserted into the database? On Wed, 2003-03-12 at 08:51, Sysadmin@saginawcontrol.com wrote: How would one go about doing this? -----Original Message----- From: Dan Hardiker [mailto:dhardiker@staff.firstcreative.net] Sent: Wednesday, March 12, 2003 8:44 AM To: Sysadmin@saginawcontrol.com Cc: dante@mail.telepac.pt; php-general@lists.php.net Subject: RE: [PHP] Hacker problem This could still be faked easily with a telnet session and some fake http headers. Your only way of making sure is to create a serverside script which filters the data.-- The above message is encrypted with double rot13 encoding. Any unauthorized attempt to decrypt it will be prosecuted to the full extent of the law.Yes, theoretically...you could require it to be posted data. In order to do this you would have to make sure "registered_globals" is set to "off" in your php.ini and then for each variable posted from yourformyou will need to do something like this.... $name=$_POST["name"]; This will only post the variables if they have been "posted." Thenyoucould use the referrer along with this and it will only allow datafromthat specific form. Hope this helps! Brian Drexler -----Original Message----- From: Pag [mailto:dante@mail.telepac.pt] Sent: Wednesday, March 12, 2003 8:35 AM To: php-general@lists.php.net Subject: [PHP] Hacker problem Been having some hacker problems on my site, and a simple one: I have a shoutbox, a simple form with name and text that adds lines to the database. I do checks for insults, too long words, tags, etc, but its still possible to circumvent those checks by adding the data on the url instead of using the form. something like: www.domain.com/shoutb.php?name=hacker&text=generalnonsenseandbadwords To prevent this, i tried tracing the http_referral so that only data from inside the site goes into the shoutbox. THe problem is that if you do that url above after visiting my site, the http_referral obviously thinks its coming from inside the site. :-P How can i solve this? Is there any way to prevent data addingfromoutside? Maybe some invisible check on the form or something? Thanks. Pag -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php