WebApp Sec mailing list archives
Re: HTTP REFERER not set in Internet Explorer
From: Jonathan Angliss <jon () netdork net>
Date: Wed, 16 Nov 2005 22:30:43 -0600
Hello Saqib, Wednesday, November 16, 2005, 10:16:33 AM, you wrote:
Because of some security concerns I need the HTTP_REFERER to be set correctly. If it is not possible, I will have to restrict my users to a Mozilla based browser.
I wouldn't recommend relying on just the headers to do your securing. They can easily be forged. There are at least two FireFox extensions that allow you to tweak them, and talking to an http server over telnet isn't that difficult, you can even precraft it in notepad. You might find your issue is in the fact that the javascript url call isn't making IE send the referrers, however if you use: <a href="yoururl.php">click here</a> You will see the referrer headers just fine. -- Jonathan Angliss <jon () netdork net>
Attachment:
_bin
Description:
Current thread:
- HTTP REFERER not set in Internet Explorer Saqib Ali (Nov 16)
- Re: HTTP REFERER not set in Internet Explorer Marc Koschewski (Nov 17)
- Re: HTTP REFERER not set in Internet Explorer Tobias Schlitt (Nov 17)
- Re: HTTP REFERER not set in Internet Explorer Amit Klein (AKsecurity) (Nov 17)
- Re: HTTP REFERER not set in Internet Explorer Jonathan Angliss (Nov 17)
- Re: HTTP REFERER not set in Internet Explorer George Johnson (Nov 17)
- Re: HTTP REFERER not set in Internet Explorer Chris Varenhorst (Nov 17)
- Re: HTTP REFERER not set in Internet Explorer Todd Hendricks (Nov 17)
- Re: HTTP REFERER not set in Internet Explorer Dean H. Saxe (Nov 17)
- Re: HTTP REFERER not set in Internet Explorer Greg Skouby (Nov 17)
- RE: HTTP REFERER not set in Internet Explorer Richard M. Smith (Nov 17)
- Re: HTTP REFERER not set in Internet Explorer Oleg Lecinski (Nov 17)
- <Possible follow-ups>
- RE: HTTP REFERER not set in Internet Explorer Amichai Shulman (Nov 17)
- RE: HTTP REFERER not set in Internet Explorer Jeff Robertson (Nov 17)
- RE: HTTP REFERER not set in Internet Explorer Einecker, Leah (Nov 17)
(Thread continues...)
- Re: HTTP REFERER not set in Internet Explorer Marc Koschewski (Nov 17)
