Referer checking is able to be referer spoofed

From: Date: Fri, 18 Mar 2005 14:55:47 +0000
Subject: Referer checking is able to be referer spoofed
Groups: php.general 
Request: Send a blank email to php-general+get-211047@lists.php.net to get a copy of this message
Hi there I am building a syndicate feed system for a client, it is based on referer checking and a id is passed over, I could do what I do with the expired url and generate a random string of some sort to login the user automatically, but then it relies on the third party to have php. I have tested with a referer spoofing app, and its true, it will still let you through if you end up putting in the correct referring domain which is join via the database. Is there another way around this ?

« previous php.general (#211047) next »