| 
 Posted by cmcnaught on 09/13/05 11:37 
Thanks for explaining that, I was wondering myself what the purpose 
was, I see the game now. I've stopped it now with the technique I 
mentioned in my last post.  At least it's put the barrier higher but 
ultimately it looks as if server side validation should be mandatory as 
well. This would have to cover all form input echoed in the email so 
could be more than trivial. 
Any other ideas of making sure the processing script is called from the 
right form would be appreciated.  Is there any way in the form to truly 
hide what value will be sent for one of the posted variables? 
cj
 
[Back to original message] 
 |