RE: [PHP] security
| From: | Boget, Chris | Date: | Fri, 23 Mar 2001 18:50:42 +0000 |
| Subject: | RE: [PHP] security | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-45325@lists.php.net to get a copy of this message | ||
> check HTTP_REFERER. If it's not your server. toss it. It's
> not the most secure way but check the page, there are other
> variables you can use to accomplish the same thing.
Even better (and it'll *always* work as far as I know), check
$HTTP_HOST.
Chris