2 ms·
Spoofing it in a client's browser is not possible but it's trivial to spoof referrer headers (or anything else) from a stand alone program. Beyond checking for
by sehrope 13y ago
Spoofing it in a client's browser is not possible but it's trivial to spoof referrer headers (or anything else) from a stand alone program. Beyond checking for referrer headers the server should give the client a signed token (returned back by the client to the server) to verify the request is valid. Otherwise if the client is arbitrarily sending requests to the server to "install X, run Y, ..." it'd be very easy to hijack the server for other processing.
As usual this goes back to one of the standard rules of server security: Don't trust anything that comes from the client.
- iooi 13y agoSpoofing with a client is easily done. In Firefox you can use TamperData.