Re: Change the anti spam function

From: Date: Tue, 12 Dec 2000 15:56:50 +0000
Subject: Re: Change the anti spam function
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-29899@lists.php.net to get a copy of this message
In article <3A36453C.8BF1FF70@torontonian.com>, John@torontonian.com (John Oktay Ozturk) wrote: > On the below code I want to be able replace the automatic domain name > checking to a domain name that I specify. > How can I do that. > My problem is I use 2 domains on the same IP with a hosting company > using Rewrite and when I use this script on the second domain it gives > me error message > > Thanx > > if (!eregi($SERVER_NAME, $HTTP_REFERER)): You would need to read up on the regular expressions and hard-code both server names. Possibly the following might work: if (!eregi('server1.domain1|server2.domain2',$HTTP_REFERER)): Although if $HTTP_REFERER is the full referer, I'm not sure how useful it is as a security check. Easy way for anyone to bypass it would be to create a folder with the same name as one of your servers and place the fake submission forms in that folder. It might make more sense to pull the hostname out of $HTTP_REFERER before doing the check above. Jerry -- http://www.hoboes.com/jerry/ "Give a man a fish and you feed him for a day. Teach him to fish, and you've depleted the lake."--It Isn't Murder If They're Yankees (http://www.hoboes.com/jerry/Murder/)

« previous php.general (#29899) next »