note 57083 deleted from reserved.variables by didou
| From: | didou@php.net | Date: | Sun, 23 Apr 2006 23:06:24 +0000 |
| Subject: | note 57083 deleted from reserved.variables by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-109259@lists.php.net to get a copy of this message | ||
Note Submitter: Kniht
----
RE: Zoic
While checking the referrer sounds like a good idea, this can simply be spoofed by any exploit
attempts. It may help deter feeble attempts, but you will also lose any visitors whose browser or
proxy strips referrer information.
Since you can't rely on it and must use other validation as well, and since it has the
potential to lose valid visitors, I don't see a reason to check it.