Reply to Re: PHP Passing Variables Between Pages and Security

Your name:

Reply:


Posted by Skeets on 10/17/46 11:39

Justin, thanks for the script. i think i get the basic idea, but i'm
missing one point. what is to stop someone from copying the script
form the first page, saving it on their computer and then pointing it
to the second page? it would seem that they could spoof it as long as
they had the code from the first page.

i see isset($_POST['formToken']) is checked, but that is independent of
the sending site, right?

isset($_SESSION['token']) is checked, but that is independent of the
sending site, right?

$_POST['formToken']==$_SESSION['token'] is checked, but, as long as the
first form's hidden element arrangement is the same, they would be
equal coming from a spoofing site, too, right?

the values would be different from those sent form the legit page, but
they would still equate to each other - and that's what is checked here
- their equality, not their aboslute values - which would be different,
of course.

or am i missing something here?

thanks to all for the good ideas.

[Back to original message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация