Re: Writing Secure PHP Scripts
| From: | Chris Adams | Date: | Thu, 07 Sep 2000 01:18:24 +0000 |
| Subject: | Re: Writing Secure PHP Scripts | ||
| References: | 1 2 3 4 5 | Groups: | php.qa |
| Request: | Send a blank email to php-qa+get-1248@lists.php.net to get a copy of this message | ||
> > > hmm, I´d call it very much easier to perform a little referrer_check
> > > against TrustedPages (TM) and even
> > > then your 1-3 should be done in addition
> >
> > Referer is just as spoofable as GPC, no?
>
> Hm, it think it´s harder to spoof or is it as simple as POST. I´m pretty
> unsure which data you can definitely trust, well then there´s always one
> way you can identify trusted pages.
> Would be interesting to know which data cannot be spoofed.
Anything sent by the client cannot be trusted. This includes GET, POST, all
HTTP headers (e.g. Referer, cookies, etc.). The only thing which cannot be
spoofed is the remote IP address. (More accurately, spoofing TCP is a very
hard thing to do; if you're using a decent operating system, TCP packets
should be almost impossible to fake without getting responses back from the
server)
If you need something to be secure, use a session library for authentication
and do not send accept any data from the client which they aren't allowed to
change at that point.