Re: script to script

From: Date: Thu, 09 May 2002 17:30:23 +0000
Subject: Re: script to script
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-96841@lists.php.net to get a copy of this message
Keep in mind that HTTP_REFERER can be faked with very little effort, so don't rely on this as an absolute security measure. miguel On Wed, 8 May 2002, Jas wrote: > That worked very well, I appriciate you giving me an example to go from. > Jas > > "Kevin Stone" <kevin@helpelf.com> wrote in message > news:000c01c1f6c6$fe370260$6601a8c0@kevin... > > Well let's say your form is at > > "http://www.yourdomain.com/form.html". And > > your confirmation script is at > > "http://www.yourdomain.com/http/confirm.php". > > Looking for the entire > exact > > URL may prove unreliable if you make any changes to your website. Looking > > for a partial domain will ensure security and you won't be nagged with > > errors resulting from changes. So the security portion of your script > might > > be as simple as this. Becuase you're looking for the domain at the > > beginning of the referral string it is completely unspoofable. > > > > <? > > // Hard code the domain into the script. > > $domain_a = 'http://www.yourdomain.com'; > > > > //Ensure the domain is at the beginning of the referral string. > > $length = strlen($domain_a); > > $domain_b = substr($HTTP_REFERER, 0, $length); > > > > if ($domain_a != $domain_b){ > > echo "INVALID ENTRY"; > > exit; > > } > > ?> > > > > Good luck! > > -Kevin > > > > ----- Original Message ----- > > From: "Jas" <jlgerfen@hotmail.com> > > To: <php-general@lists.php.net> > > Sent: Wednesday, May 08, 2002 11:57 AM > > Subject: Re: [PHP] script to script > > > > > > > Could you give me an example of this? > > > thanks again, > > > jas > > > > > > "Kevin Stone" <kevin@helpelf.com> wrote in message > > > news:006601c1f6b8$8a00ad00$6601a8c0@kevin... > > > > The variable $HTTP_REFERER stores the last URL visited by the browser. > > > It > > > > is set by the browser its self so contents may vary. But you can > > hardcode > > > > the URL into your script then perform a soft comparison between the > two. > > > If > > > > there are too many differences then you simply deny the request. Hope > > > this > > > > helps. > > > > > > > > -Kevin > > > > > > > > ----- Original Message ----- > > > > From: "Jas" <jlgerfen@hotmail.com> > > > > To: <php-general@lists.php.net> > > > > Sent: Wednesday, May 08, 2002 11:38 AM > > > > Subject: [PHP] script to script > > > > > > > > > > > > > I have a form that links from a form on an html page then to a > confirm > > > > page, > > > > > I have error validation on each page however on the final page I > would > > > > like > > > > > to have it verify where the data is coming from... i.e. I would like > > to > > > > make > > > > > sure it is coming from the confirm page on the same server. If > anyone > > > has > > > > > an idea of how to accomplish this that would be great. Thanks in > > > advance, > > > > > jas > > > > > > > > > > > > > > > > > > > > -- > > > > > PHP General Mailing List (http://www.php.net/) > > > > > To unsubscribe, visit: > > > > > http://www.php.net/unsub.php > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > -- > > > PHP General Mailing List (http://www.php.net/) > > > To unsubscribe, visit: http://www.php.net/unsub.php > > > > > > > > > > > > > >

« previous php.general (#96841) next »