Security issue
| From: | Geraud P. Krawezik | Date: | Wed, 13 Dec 2000 16:28:35 +0000 |
| Subject: | Security issue | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-30100@lists.php.net to get a copy of this message | ||
Hi,
I'm making a PHP webpage, and would like to be able from where this page is
called, in order to reduce the possible number of callers to a predefined
list.
Thus, I've had a look into getenv(HTTP_REFERER). The problem is that if
somebody is using the same name or ip in its own local network, then he can
connect by redirecting his request to my page.
The big question is so: is there a possibility to allow only connection
between pages located in the same LAN? but be careful, this pages will also
be read over the internet. What i want to avoid is the call of my
'protected'web pages from 'untrusted'pages...
Thanks ...
Geraud
____________________________________________________________________
Géraud P. Krawezik www.chez.com/krawezge
ENSIETA Graduate www.ensieta.fr
PhD Student www.lri.fr
Artabel Engineer www.artabel.net +33(0)1 69 18 95 86