Re: Writing Secure PHP Scripts

From: Date: Thu, 07 Sep 2000 01:18:24 +0000
Subject: Re: Writing Secure PHP Scripts
References: 1 2 3 4 5  Groups: php.qa 
Request: Send a blank email to php-qa+get-1248@lists.php.net to get a copy of this message
> > > hmm, I´d call it very much easier to perform a little referrer_check > > > against TrustedPages (TM) and even > > > then your 1-3 should be done in addition > > > > Referer is just as spoofable as GPC, no? > > Hm, it think it´s harder to spoof or is it as simple as POST. I´m pretty > unsure which data you can definitely trust, well then there´s always one > way you can identify trusted pages. > Would be interesting to know which data cannot be spoofed. Anything sent by the client cannot be trusted. This includes GET, POST, all HTTP headers (e.g. Referer, cookies, etc.). The only thing which cannot be spoofed is the remote IP address. (More accurately, spoofing TCP is a very hard thing to do; if you're using a decent operating system, TCP packets should be almost impossible to fake without getting responses back from the server) If you need something to be secure, use a session library for authentication and do not send accept any data from the client which they aren't allowed to change at that point.

« previous php.qa (#1248) next »