Posted by cmcnaught on 09/13/05 11:37
Thanks for explaining that, I was wondering myself what the purpose
was, I see the game now. I've stopped it now with the technique I
mentioned in my last post. At least it's put the barrier higher but
ultimately it looks as if server side validation should be mandatory as
well. This would have to cover all form input echoed in the email so
could be more than trivial.
Any other ideas of making sure the processing script is called from the
right form would be appreciated. Is there any way in the form to truly
hide what value will be sent for one of the posted variables?
cj
Navigation:
[Reply to this message]
|