Re: Munging hidden/form variables

From: Date: Fri, 02 Mar 2001 10:21:35 +0000
Subject: Re: Munging hidden/form variables
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-42324@lists.php.net to get a copy of this message
On Friday 02 March 2001 00:22, you wrote: > I can think of one way that you can take in an attempy to prevent > this. > It is not totally fool proof but it will make it more difficult > to send spoof data: > > 1) Check your HTTP refereer when the form is submitted. If the > referer is not from your host then don't process the form. > Of course this can be faked quite easily if this person knows > what (s)he doing. And it would prevent people who don't sent Referrer headers from using the form -- Christian Reiniger LGDC Webmaster (http://sunsite.dk/lgdc/) The use of COBOL cripples the mind; its teaching should, therefore, be regarded as a criminal offence. - Edsger W. Dijkstra

« previous php.general (#42324) next »