Re: form security problem
| From: | Scott Fletcher | Date: | Wed, 11 Oct 2000 21:53:10 +0000 |
| Subject: | Re: form security problem | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-19709@lists.php.net to get a copy of this message | ||
Unfortunately, the environment variable, "HTTP_REFERRER" or "HTTP_REFERER"
doesn't work in Netscape 6.0 and it is not know if it will work at all in
that newer version.
Scott
"Mark Peoples" <gascsd@gascairlines.com> wrote in message
news:BMEEJBCNBFEMOACLJPNGOEEFCAAA.gascsd@gascairlines.com...
> Someone will probably come up with a better idea, but here goes.
>
> Since HTTP_REFERRER probably won't suffice (eg, they can just add the
> ?test=0 to the end of the URL), I'd probably say some sort of hashing
scheme
> with mcrypt, or random numbers?
>
> marco
>
> -----Original Message-----
> From: Vojt?ch Patrný [mailto:patrnyv@yahoo.com]
> Sent: Wednesday, October 11, 2000 10:58 AM
> To: php-general@lists.php.net
> Subject: [PHP] form security problem
>
>
> Hi,
> I`ve a problem with my php app.
>
> I use this code :
> (form action="a.php")
> (input name="test" type="text" value="0")
> (input type="submit")
> (/form)
>
> The problem is that anybody can save this page on
> his computer and edit the value="xx" and then send
> it to my DB. I need to filter if it cames from my site.
> Can somebody help me please?
>
> Data in value change every time so it`s
> imposible to make a db filter.
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>