Referer checking is able to be referer spoofed
| From: | Dan Rossi | Date: | Fri, 18 Mar 2005 14:55:47 +0000 |
| Subject: | Referer checking is able to be referer spoofed | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-211047@lists.php.net to get a copy of this message | ||
Hi there I am building a syndicate feed system for a client, it is based on referer checking and a id is passed over, I could do what I do with the expired url and generate a random string of some sort to login the user automatically, but then it relies on the third party to have php. I have tested with a referer spoofing app, and its true, it will still let you through if you end up putting in the correct referring domain which is join via the database. Is there another way around this ?