Re: Munging hidden/form variables
| From: | Christian Reiniger | Date: | Fri, 02 Mar 2001 10:21:35 +0000 |
| Subject: | Re: Munging hidden/form variables | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-42324@lists.php.net to get a copy of this message | ||
On Friday 02 March 2001 00:22, you wrote:
> I can think of one way that you can take in an attempy to prevent
> this.
> It is not totally fool proof but it will make it more difficult
> to send spoof data:
>
> 1) Check your HTTP refereer when the form is submitted. If the
> referer is not from your host then don't process the form.
> Of course this can be faked quite easily if this person knows
> what (s)he doing.
And it would prevent people who don't sent Referrer headers from using
the form
--
Christian Reiniger
LGDC Webmaster (http://sunsite.dk/lgdc/)
The use of COBOL cripples the mind; its teaching should, therefore,
be regarded as a criminal offence.
- Edsger W. Dijkstra