Fw: [PHP] script to script

From: Date: Wed, 08 May 2002 19:31:40 +0000
Subject: Fw: [PHP] script to script
Groups: php.general 
Request: Send a blank email to php-general+get-96633@lists.php.net to get a copy of this message
Well let's say your form is at "http://www.yourdomain.com/form.html". And your confirmation script is at "http://www.yourdomain.com/http/confirm.php". Looking for the entire exact URL may prove unreliable if you make any changes to your website. Looking for a partial domain will ensure security and you won't be nagged with errors resulting from changes. So the security portion of your script might be as simple as this. Becuase you're looking for the domain at the beginning of the referral string it is completely unspoofable. <? // Hard code the domain into the script. $domain_a = 'http://www.yourdomain.com'; //Ensure the domain is at the beginning of the referral string. $length = strlen($domain_a); $domain_b = substr($HTTP_REFERER, 0, $length); if ($domain_a != $domain_b){ echo "INVALID ENTRY"; exit; } ?> Good luck! -Kevin ----- Original Message ----- From: "Jas" <jlgerfen@hotmail.com> To: <php-general@lists.php.net> Sent: Wednesday, May 08, 2002 11:57 AM Subject: Re: [PHP] script to script > Could you give me an example of this? > thanks again, > jas > > "Kevin Stone" <kevin@helpelf.com> wrote in message > news:006601c1f6b8$8a00ad00$6601a8c0@kevin... > > The variable $HTTP_REFERER stores the last URL visited by the browser. > It > > is set by the browser its self so contents may vary. But you can hardcode > > the URL into your script then perform a soft comparison between the two. > If > > there are too many differences then you simply deny the request. Hope > this > > helps. > > > > -Kevin > > > > ----- Original Message ----- > > From: "Jas" <jlgerfen@hotmail.com> > > To: <php-general@lists.php.net> > > Sent: Wednesday, May 08, 2002 11:38 AM > > Subject: [PHP] script to script > > > > > > > I have a form that links from a form on an html page then to a confirm > > page, > > > I have error validation on each page however on the final page I would > > like > > > to have it verify where the data is coming from... i.e. I would like to > > make > > > sure it is coming from the confirm page on the same server. If anyone > has > > > an idea of how to accomplish this that would be great. Thanks in > advance, > > > jas > > > > > > > > > > > > -- > > > PHP General Mailing List (http://www.php.net/) > > > To unsubscribe, visit: http://www.php.net/unsub.php > > > > > > > > > > > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php > >

« previous php.general (#96633) next »