note 51898 added to function.output-add-rewrite-var
| From: | qbolec at osu1 dot php dot net | Date: | Thu, 14 Apr 2005 12:46:34 +0000 |
| Subject: | note 51898 added to function.output-add-rewrite-var | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-87995@lists.php.net to get a copy of this message | ||
I'm using this function in control panel, to append md5(session_id()) to each form and link in
this panel. I also check when receiving data in control panel, if it contains this md5. I think
it's quite good way to prevent the attack, where the user posts an image to the forum, but
instead of image url, it specifies the url to control panel with some instructions. You should also
check if the data come from the source you intended (GET or POST?).
----
Manual Page -- http://www.php.net/manual/en/function.output-add-rewrite-var.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+51898
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+51898&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+51898&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+51898&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+51898&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+51898&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+51898&report=yes
Search -- http://master.php.net/manage/user-notes.php