hmm, I´d call it very much easier to perform a little referrer_check
against TrustedPages (TM) and even
then your 1-3 should be done in addition
Referer is just as spoofable as GPC, no?
Hm, it think it´s harder to spoof or is it as simple as POST. I´m pretty unsure which data you can definitely trust, well then there´s always one way you can identify trusted pages.
Would be interesting to know which data cannot be spoofed.
You should use one-way randomized encrypted transaction numbers which have to go through the ether too and which can only used once in defined period of time but it all more complicated then.
You´ll need a table to store them at client and at server time, at client side (if you use one table for many pages) you need to lock these tables, unless you can´t SELECT and DELETE in one turn, and before these transactionnumbers are used up you need to refresh theses numbers and son on...
Thus we´ve got some levels of security
server level
1) Don´t care whether data comes from GET,POST whatever sources.
2) Only use the method data you´re expecting result to come from.
3) " " + REFERER_CHECK
script level
1) Don´t care if passed data is valid, expected
2) Check if passed data meets several requirements (integers beeing in the range of..., strings not containing several characters...) and apply corrections to them
? level
1) use transactional communication
andré
ps. glad to return to productive levels :)
--
· André Langhorst · t: +49 571 3201801 ·
· waldschrott@php.net · m: +49 173 9558736 ·
· PHP Quality Assurance · http://qa.php.net ·