Re: script to script
| From: | Miguel Cruz | Date: | Thu, 09 May 2002 17:30:23 +0000 |
| Subject: | Re: script to script | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-96841@lists.php.net to get a copy of this message | ||
Keep in mind that HTTP_REFERER can be faked with very little effort, so
don't rely on this as an absolute security measure.
miguel
On Wed, 8 May 2002, Jas wrote:
> That worked very well, I appriciate you giving me an example to go from.
> Jas
>
> "Kevin Stone" <kevin@helpelf.com> wrote in message
> news:000c01c1f6c6$fe370260$6601a8c0@kevin...
> > Well let's say your form is at
> > "http://www.yourdomain.com/form.html". And
> > your confirmation script is at
> > "http://www.yourdomain.com/http/confirm.php".
> > Looking for the entire
> exact
> > URL may prove unreliable if you make any changes to your website. Looking
> > for a partial domain will ensure security and you won't be nagged with
> > errors resulting from changes. So the security portion of your script
> might
> > be as simple as this. Becuase you're looking for the domain at the
> > beginning of the referral string it is completely unspoofable.
> >
> > <?
> > // Hard code the domain into the script.
> > $domain_a = 'http://www.yourdomain.com';
> >
> > //Ensure the domain is at the beginning of the referral string.
> > $length = strlen($domain_a);
> > $domain_b = substr($HTTP_REFERER, 0, $length);
> >
> > if ($domain_a != $domain_b){
> > echo "INVALID ENTRY";
> > exit;
> > }
> > ?>
> >
> > Good luck!
> > -Kevin
> >
> > ----- Original Message -----
> > From: "Jas" <jlgerfen@hotmail.com>
> > To: <php-general@lists.php.net>
> > Sent: Wednesday, May 08, 2002 11:57 AM
> > Subject: Re: [PHP] script to script
> >
> >
> > > Could you give me an example of this?
> > > thanks again,
> > > jas
> > >
> > > "Kevin Stone" <kevin@helpelf.com> wrote in message
> > > news:006601c1f6b8$8a00ad00$6601a8c0@kevin...
> > > > The variable $HTTP_REFERER stores the last URL visited by the browser.
> > > It
> > > > is set by the browser its self so contents may vary. But you can
> > hardcode
> > > > the URL into your script then perform a soft comparison between the
> two.
> > > If
> > > > there are too many differences then you simply deny the request. Hope
> > > this
> > > > helps.
> > > >
> > > > -Kevin
> > > >
> > > > ----- Original Message -----
> > > > From: "Jas" <jlgerfen@hotmail.com>
> > > > To: <php-general@lists.php.net>
> > > > Sent: Wednesday, May 08, 2002 11:38 AM
> > > > Subject: [PHP] script to script
> > > >
> > > >
> > > > > I have a form that links from a form on an html page then to a
> confirm
> > > > page,
> > > > > I have error validation on each page however on the final page I
> would
> > > > like
> > > > > to have it verify where the data is coming from... i.e. I would like
> > to
> > > > make
> > > > > sure it is coming from the confirm page on the same server. If
> anyone
> > > has
> > > > > an idea of how to accomplish this that would be great. Thanks in
> > > advance,
> > > > > jas
> > > > >
> > > > >
> > > > >
> > > > > --
> > > > > PHP General Mailing List (http://www.php.net/)
> > > > > To unsubscribe, visit:
> > > > > http://www.php.net/unsub.php
> > > > >
> > > > >
> > > >
> > > >
> > >
> > >
> > >
> > > --
> > > PHP General Mailing List (http://www.php.net/)
> > > To unsubscribe, visit: http://www.php.net/unsub.php
> > >
> > >
> >
> >
>
>
>
>