Re: Validating user referring host

From: Jonas Kongslund (dont_at_mail.me.at.all)
Date: 11/20/03


Date: Thu, 20 Nov 2003 02:07:34 +0100

Mark F wrote:

> What is the best way to ensure that a user who is entering your
> application can only come to it through a particular server.

Please elaborate on this. I'm not quite sure I understand your question.

> We were using a tomcat
> filter to check the refer string, parsing out the hostname, but that does
> not seem to be reliable.

Indeed, that is not very reliable. Anybody can fake the referer header and
clients are not obligated to send it at all.

See section 10.34 of the HTTP/1.1 specification:
<http://www.w3.org/Protocols/HTTP/1.1/spec.html#Referer>

-- 
Jonas Kongslund


Relevant Pages

  • RE: error message
    ... You the Client:: send a User name and Password to the server which is your ... Hello Dale how things (while the is checking your ... 'automatically detect settings', which was unticked. ... Mark that the only time I got rid of this annoying message is when I ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: suggest guest book
    ... Mark! ... You'll abandon killings. ... server. ... He can properly favour towards stiff jolly corridors. ...
    (sci.crypt)
  • Re: Execution Timeout Problem
    ... Hi Mark, ... In addition to Brock's suggestion on make your serverside processing ... you can also check whether you've apply any Timeout setting at ... you need to access the server somehow to initiate the long ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Synchronizing two servers
    ... > Mark, while it's probably possible with VPN, File transfers etc, it's ... > VPN, OWA until the server came over. ...
    (microsoft.public.windows.server.sbs)
  • Re: 21st Century repeat of ~ Sodom & Gomorrah ~
    ... then when Mark clears the motobot our posts get through ... The problem affects anyone who uses the main news server provided by ... Virgin Media couldn't even fix my cable TV service and internet. ...
    (uk.religion.christian)