Re: security
| From: | py | Date: | Tue, 10 Jul 2001 13:04:29 +0000 |
| Subject: | Re: security | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-57223@lists.php.net to get a copy of this message | ||
But remember that once a user has accessed the .swf once, they can then
get the path and call the file directly afterwards. Even worse, the .swf is
in the computer's cache.
py
----- Original Message -----
From: Chris Lambert - WhiteCrown Networks <chris@whitecrown.net>
To: AVisioN:::nomoremedia::: <info@nomoremedia.de>
Cc: <php-general@lists.php.net>
Sent: Tuesday, July 10, 2001 5:30 PM
Subject: Re: [PHP] security
> Check what the user agent is for the SWF, and see if it passes a specific
> referer. That should deter 99% of attempts.
>
> /* Chris Lambert, CTO - chris@whitecrown.net
> WhiteCrown Networks - More Than White Hats
> Web Application Security - www.whitecrown.net
> */
>
> ----- Original Message -----
> From: AVisioN:::nomoremedia::: <info@nomoremedia.de>
> To: <php-general@lists.php.net>
> Sent: Tuesday, July 10, 2001 12:08 PM
> Subject: [PHP] security
>
>
> | Is it possible to restrict the use of a php-file to a special file (for
> | example an swf).
> |
> |
> | --
> | ---::::: AVisioN :::::---
> | http://www.nomoremedia.de
> | -::info@nomoremedia.de::-
> |
> | "I have nothing to declare except my genius"._oscar_wild
> |
> |
> |
> | --
> | PHP General Mailing List (http://www.php.net/)
> | To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> | For additional commands, e-mail: php-general-help@lists.php.net
> | To contact the list administrators, e-mail: php-list-admin@lists.php.net
> |
> |
> |
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>