note 51898 deleted from function.output-add-rewrite-var by nlopess
| From: | nlopess@php.net | Date: | Fri, 15 Sep 2006 13:04:55 +0000 |
| Subject: | note 51898 deleted from function.output-add-rewrite-var by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-117220@lists.php.net to get a copy of this message | ||
Note Submitter: qbolec
----
I'm using this function in control panel, to append md5(session_id()) to each form and link in
this panel. I also check when receiving data in control panel, if it contains this md5. I think
it's quite good way to prevent the attack, where the user posts an image to the forum, but
instead of image url, it specifies the url to control panel with some instructions. You should also
check if the data come from the source you intended (GET or POST?).