5 ms·
How is spoofing the referer extremely easy? I can think of no way for an attack site to do this, short of having control over the entire user machine (or a sign
by personalcompute 15y ago
How is spoofing the referer extremely easy? I can think of no way for an attack site to do this, short of having control over the entire user machine (or a significant browser exploit anyways), at which point all of your webapp security is irrelevant.
- sonnym 15y agoYou cannot assume a request is coming from a browser. curl --referer http://www.example.come http://www.example.come http://www.example.com http://www.example.com
- personalcompute 15y agoYes, but if the user wishes to avoid their own security like this, they can already do it a thousand other ways (and to no adverse affect, there is no opportunity for an attacker to exploit this, I don't know what you're getting at).
- sonnym 15y agoI was merely pointing out how easy it is to fake, although you are correct a third party site could not do this. Atwood's point is that checking the "referer" will both be unreliable and, more importantly, lead to false positives; there are better alternatives, namely, double submitting cookies as I have pointed out elsewhere with regard to this article.
- personalcompute 15y agoHe's definitely correct about the false positives and that nonces and/or double submitted cookies are superior, I'm not arguing that, just the 'furthermore, spoofing is extremely easy,' which makes no sense there.