Re: Hacker problem
| From: | Mirek Novak | Date: | Thu, 13 Mar 2003 07:43:22 +0000 |
| Subject: | Re: Hacker problem | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-139450@lists.php.net to get a copy of this message | ||
CPT John W. Holmes wrote:
This is no good unless you're saving the value server side somewhere. With this method, I can still post to your page from anywhere, so long as I set the two variables the same. Who cares if the data came from your page, just validate it! No matter what you do, it can be defeated. Even if you come up with a random code, store it in the database, place it on the page, and make sure they match, all I have to do is write my PHP script so it requests your page, matches the code, and then generates a couple hundred posts based on that code. Or it can just run through a loop of request, match, post and do it hundreds of time a second. simple javascript [write('<code>'); ] will solve this. :)
---John Holmes...Sure, but it _costs_ something, I mean, you have to spend time or money or both to do this. So if this is as important as you do it, for your oponent it must be little more important to fight it. In this case, webmasters acquisitions must "cost" little more than an attacker is agreeable to spent on it. :) -- Mirek Novak jabber: mirek@njs.netlab.cz ICQ: 119499448