note 56992 deleted from reserved.variables by didou
| From: | didou@php.net | Date: | Sun, 23 Apr 2006 23:06:19 +0000 |
| Subject: | note 56992 deleted from reserved.variables by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-109258@lists.php.net to get a copy of this message | ||
Note Submitter: Zoic
----
I just wrote up this function to secure forms on my site so that you can't submit a form from
anywhere but your site. This is extremely effective in securing your forms from hacking attempts.
<?php
function form_post_check()
{
$referring_url = $_SERVER['HTTP_REFERER']; // get the referring URL
$host = $_SERVER['HTTP_HOST']; // get the header from the current request (example:
www.yoursite.com)
$valid_url = 'http://'.$host.'/'; // finish
defining a valid referring URL
$valid_len = strlen( $valid_url ); // get the length of the valid url
// if the valid url isn't the first part of the referring url
if ( substr( $referring_url, 0, $valid_len ) != $valid_url )
{
die( 'You submitted this form from an invalid URL.' ); // stop everything and
display a message
}
}
?>