is $HTTP_REFERER worth trusting?
| From: | Patrick Hsieh | Date: | Thu, 16 May 2002 08:53:18 +0000 |
| Subject: | is $HTTP_REFERER worth trusting? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-97877@lists.php.net to get a copy of this message | ||
Hello list,
I have a php program which executes a heavy mysql query upon request.
Normally, it should not be requested too often, but I am afraid
malicious user trying to massively call this program. I am considering
to use $HTTP_REFERER to restrict the connection source, but is it worth
trusting? Is it possible for a hacker to make an identical $HTT_REFERER
in the header? I have no idea how $HTTP_REFERER is made, is it made from
the http client and put in the http header?
If I can't trust $HTTP_REFERER, how can I deny malicious attack like
that?
--
Patrick Hsieh <pahud@pahud.net>
GPG public key http://pahud.net/pubkeys/pahudatpahud.gpg