Re: Referer checking is able to be referer spoofed

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




On 19/03/2005, at 2:36 AM, Marek Kilimajer wrote:

Dan Rossi wrote:
On 19/03/2005, at 2:06 AM, php-list-replies@xxxxxxxxxxxxxxxxxxxxx wrote:


I think you misunderstood me or I wasnt clear, the links are coming from a syndicate site to the main site, so we check on that domain. I am looking at other options, maybe someway of trasparently logging in ?

You were not clear at all. What are you trying to do?



Hi there Marek, here is how the system currently works. Each feed afiliate has a special number, this is used for publishing points on the streaming server aswell as loading refering domains from the database. A link to the video feed player window will happen from their server only, therefore the referer check. What I was trying to say is, one of the customers picked up , that it was using referer checks aswell as a few other things, and worked out referer spoofing software will let you in still. We need to try and avoid this, as each customer's authentication is different we cannot have another login as its not in sync. So we may have to look at other options, possibly someway of transparently logging in I dont know.


--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php


[Index of Archives]     [PHP Home]     [Apache Users]     [PHP on Windows]     [Kernel Newbies]     [PHP Install]     [PHP Classes]     [Pear]     [Postgresql]     [Postgresql PHP]     [PHP on Windows]     [PHP Database Programming]     [PHP SOAP]

  Powered by Linux