786 snippets from 1631 members, and growing!
|
login
|
join
about
bytebin
members
tags
snippets
join
Snippets
Submit a Snippet
Search Snippets
New Snippets
Top Snippets
Top Tags
PHP
(142)
JavaScript
(125)
Java
(66)
VBSCRIPT
(58)
String
(44)
CSS
(31)
File
(29)
CSharp
(28)
HTML
(27)
mysql
(27)
C
(24)
VB.NET
(24)
python
(24)
CPlusPlus
(23)
groovy
(23)
New Snippets
Detect Adblock
Concatenar campos...
fopen
Unique random key
get number of cha...
Find a File
Find a Directory
List Directory
File uploading in...
Get Values from C...
Venture Capital Jobs
New Members
mcheung63
cicero
mycodeofshailendra
nostromo
KennethCC
me
jamesmcm
Can
Kelmi
ysg
Top Members
dannyboy
sundaramkumar
mattrmiller
Pio
i_kenneth
ASmith
ctiggerf
sehrgut
bertheymans
SCoon
Home
/
Snippets
/
Only allow _POST's from your domain
/
Comments
Only allow _POST's from your domain
Snippet Menu
Revisions
Comments
Related Snippets
Add to Favorites
Email Snippet
Download Snippet
Print Snippet
Blog Snippet
snippet
|
revisions
|
comments
|
related
|
Add to Favorites
|
email
download
|
print
|
blog it
New Comment
Spoofing
Wed. Apr. 2nd, 2008 3:43 PM
sehrgut
Of course, you realize referrer-spoofing is trivial. If this check were actually necessary, some form of user authentication is the answer.
I've got good news, and I've got bad news:
The universe is merely a figment of my imagination.
Now are you ready for the bad news?
Reply
Token?
Wed. Aug. 29th, 2007 9:34 AM
Tr0y
Perhaps you should generate a token in your forms and check to see if the token is valid on submit.
Reply
=]
Tue. Jun. 26th, 2007 11:05 PM
loibe
Hi,
will this work even the POST was sent using Curl - where it's also possible to set the referrer?
[ akosiloibe ]
Reply
New Comment
I've got good news, and I've got bad news:
The universe is merely a figment of my imagination.
Now are you ready for the bad news?
will this work even the POST was sent using Curl - where it's also possible to set the referrer?
[ akosiloibe ]