Re: [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload]
| From: | Simon Edwards | Date: | Mon, 04 Sep 2000 05:28:06 +0000 |
| Subject: | Re: [Fwd: (SRADV00001) Arbitrary file disclosure through PHP file upload] | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15059@lists.php.net to get a copy of this message | ||
Matthew Leverton wrote:
> Another good thing to check for when a form is being submitted is the
> referrer. If you can safely assume all users are on a modern browser,
> you could disallow all form submissions that do not come from your
> domain. Typically another site should never have to POSTdata to your
> server.
I would just like to warn people to never rely on the Referrer header
for
security. Just like form values, it's an Agent of Evil under control of
the Client.
> In any case, there's a lot to be watching out for..
yes sirrie.
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990