RE: [PHP] Munging hidden/form variables
| From: | Boget, Chris | Date: | Thu, 01 Mar 2001 20:29:04 +0000 |
| Subject: | RE: [PHP] Munging hidden/form variables | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-42218@lists.php.net to get a copy of this message | ||
> Is there any way to defend against this? Is there any way
> to ensure that when a form is submitted that the submission
> request originated from your site/domain and not somewhere
> else?
Knowing that $HTTP_REFERER cannot be relied on as containing
valid data (as some browsers don't support it)?
Chris