Re: [PHP] Re: disable referer ? (was: Framed & Linked Content)
- From: per@xxxxxxxxxxxx (Per Jessen)
- Date: Thu, 31 Jan 2008 08:19:55 +0100
Richard Lynch wrote:
On Tue, January 29, 2008 12:48 pm, Per Jessen wrote:
Robert Cummings wrote:
Actually, now you made me think on it... the primary reason I
disable
referrer logging is because it will also pass along lovely
information
such as any session ID embedded in the URL. So if you happen to get
on
a malicious site, they could access the account from which you've
come.
Hmm, interesting idea. I wonder if the sessionid isn't tied to the
IP-address even when it's part of the URL?
It CANNOT be tied to the IP address, because most users' IP addresses
are not static.
I think it is for the duration of the session. Mine certainly is.
Google for "session hijacking" for more info.
Still, I can't help thinking that if this is a serious problem, it
would have been dealt with long ago.
War is a serious problem.
So is murder.
So is people cutting me off in traffic. :-v
None of them have been dealt with effectively yet.
Sure it has - nobody cuts me off in traffic here. :-)
Regardless, I did some googling and read a bit about session hijacking
and such. I still don't see much of a serious problem. When Firefox
switches off REFERER by default, we can talk again.
/Per Jessen, Zürich
.
- Follow-Ups:
- Re: [PHP] Re: disable referer ? (was: Framed & Linked Content)
- From: "Richard Lynch"
- Re: [PHP] Re: disable referer ? (was: Framed & Linked Content)
- References:
- Framed & Linked Content
- From: "Mike Potter"
- Re: [PHP] Framed & Linked Content
- From: Robert Cummings
- Re: [PHP] Framed & Linked Content
- From: Per Jessen
- Re: [PHP] Framed & Linked Content
- From: Robert Cummings
- Re: disable referer ? (was: Framed & Linked Content)
- From: Per Jessen
- Re: [PHP] Re: disable referer ? (was: Framed & Linked Content)
- From: Robert Cummings
- Re: [PHP] Re: disable referer ? (was: Framed & Linked Content)
- From: Robert Cummings
- Re: [PHP] Re: disable referer ? (was: Framed & Linked Content)
- From: Per Jessen
- Re: [PHP] Re: disable referer ? (was: Framed & Linked Content)
- From: "Richard Lynch"
- Framed & Linked Content
- Prev by Date: Re: [PHP] Framed & Linked Content
- Next by Date: Re: [PHP] how dod you get to do multiple mysql queries concurrently?
- Previous by thread: Re: [PHP] Re: disable referer ? (was: Framed & Linked Content)
- Next by thread: Re: [PHP] Re: disable referer ? (was: Framed & Linked Content)
- Index(es):