Posted by Robertico on 10/14/14 11:21
I'am intersted in a solution to create a "spam" secure mailform.
I read about domain checks but they use the $HTTP_REFERER and imo thats not
100%.
As the manual mentioned :"The address of the page (if any) which referred
the user agent to the current page.
This is set by the user agent. Not all user agents will set this, and some
provide the ability to modify HTTP_REFERER as a feature.
In short, it cannot really be trusted."
Also read something about sessions. But whats the best (secure as possible)
way to prevent using the mail form outside my domain.
Robertico
Navigation:
[Reply to this message]
|