RE: [PHP] security
| From: | Cal Evans | Date: | Fri, 23 Mar 2001 18:50:15 +0000 |
| Subject: | RE: [PHP] security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-45326@lists.php.net to get a copy of this message | ||
RE: [PHP] securityI was going to say that but I wasn't sure if $HTTP_HOST
would get the host of the page that is now executing or the host of where
the page was coming from.
Cal
http://www.calevans.com
-----Original Message-----
From: Boget, Chris [mailto:Chris.Boget@wild.net]
Sent: Friday, March 23, 2001 12:51 PM
To: 'Cal Evans'; Randy Johnson; php-general@lists.php.net
Subject: RE: [PHP] security
> check HTTP_REFERER. If it's not your server. toss it. It's
> not the most secure way but check the page, there are other
> variables you can use to accomplish the same thing.
Even better (and it'll *always* work as far as I know), check
$HTTP_HOST.
Chris