Re: Referer checking is able to be referer spoofed

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




On 20/03/2005, at 5:40 AM, Marek Kilimajer wrote:



If you need only hotlink protection then the current referer checking is just enough. Most users will not install referer spoofing software.


But if you need to be 100% sure the videos are streamed through affiliate server, you can use tokens - a script at the affiliate server will request a token from the streaming server (with username/password/clip id etc.). This token will be sent with the link to the streaming server. Hope this is clear.



Hmm its the exact setup with how the video filenames are generated in the player to prevent hotlinking. I guess I am on my own, my client has very paranoid customers as they have to pay for the bandwidth. Lets see how I go. But theoretically we must assume these people dont have php.


--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php


[Index of Archives]     [PHP Home]     [Apache Users]     [PHP on Windows]     [Kernel Newbies]     [PHP Install]     [PHP Classes]     [Pear]     [Postgresql]     [Postgresql PHP]     [PHP on Windows]     [PHP Database Programming]     [PHP SOAP]

  Powered by Linux