Re: form security problem

From: Date: Wed, 11 Oct 2000 21:53:10 +0000
Subject: Re: form security problem
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-19709@lists.php.net to get a copy of this message
Unfortunately, the environment variable, "HTTP_REFERRER" or "HTTP_REFERER" doesn't work in Netscape 6.0 and it is not know if it will work at all in that newer version. Scott "Mark Peoples" <gascsd@gascairlines.com> wrote in message news:BMEEJBCNBFEMOACLJPNGOEEFCAAA.gascsd@gascairlines.com... > Someone will probably come up with a better idea, but here goes. > > Since HTTP_REFERRER probably won't suffice (eg, they can just add the > ?test=0 to the end of the URL), I'd probably say some sort of hashing scheme > with mcrypt, or random numbers? > > marco > > -----Original Message----- > From: Vojt?ch Patrný [mailto:patrnyv@yahoo.com] > Sent: Wednesday, October 11, 2000 10:58 AM > To: php-general@lists.php.net > Subject: [PHP] form security problem > > > Hi, > I`ve a problem with my php app. > > I use this code : > (form action="a.php") > (input name="test" type="text" value="0") > (input type="submit") > (/form) > > The problem is that anybody can save this page on > his computer and edit the value="xx" and then send > it to my DB. I need to filter if it cames from my site. > Can somebody help me please? > > Data in value change every time so it`s > imposible to make a db filter. > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#19709) next »