Google Community
Latest Forums Rules Resources
Custom Search

Go Back   Google Community > The Community > General Discussion

GoogleCommunity Sponsor
Cirtex Hosting
Use coupon "forum" for 50% Off!

Reply
 
LinkBack Thread Tools Display Modes
Old 02-06-2005, 12:14 AM   #1 (permalink)
Google Guru
 
Join Date: Jan 2005
Location: Deep in the heart.
Posts: 2,443
Thanks: 0
Thanked 3 Times in 3 Posts
geekerati is an unknown quantity at this point
Referer Buys You Nothing

Chris Shiflett's Blog: Referer Buys You Nothing
2.04.2005 07:59:42 CST



Quote:
I am very surprised at how often I see Referer checking being mentioned as a safeguard against form spoofing. I can't properly express how completely useless this is. I've even had people try to argue with me, convinced that this is a sound technique.

Too many systems use this kind of authentication to ensure that the posted value comes from their own site, but, as he mentions, that is too easily spoofed. His suggestion for a added bit of security? Make a key in a hidden attribute that's unique to that loading of the form but can still be checked once the values are submitted.
PHP Developer
geekerati is offline   Reply With Quote
 
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Adobe Buys Macromedia HHH The Game General Discussion 1 05-15-2006 08:56 AM
Google buys Measure Map geekerati Other Google Features 1 02-16-2006 05:02 PM
Google buys Dodgeball geekerati All About Google 7 05-14-2005 03:01 AM
Google buys Urchin geekerati Other Google Features 1 04-13-2005 09:34 PM
Look out, Google: Microsoft Buys Looksmart intelliot Gmail Forum 10 07-21-2004 02:32 AM


All times are GMT -8. The time now is 01:55 AM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0
© 2004–2007 Google Community