[21088] in bugtraq

home help back first fref pref prev next nref lref last post

Re: The Dangers of Allowing Users to Post Images

daemon@ATHENA.MIT.EDU (Jason Brooke)
Tue Jun 19 01:47:17 2001

Message-ID: <00ad01c0f6d1$6aaa0920$58c2a4cb@rochd1.qld.optushome.com.au>
From: "Jason Brooke" <jb@qgl.org>
To: "Chris Lambert" <clambert@gamespy.com>
Cc: <bugtraq@securityfocus.com>
Date: Sun, 17 Jun 2001 12:01:26 +1000
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

> The discussion is about preventing the users machine being "attacked"
> unknowingly. A user faking a referer themselves isn't going to be a problem,
> as not only would they be authorizing the action, but they'd be going out of
> their way to make sure it got through. Read up on the first post to see what
> this discussion is actually about.

Popular software that strips out Referer headers is utilised by many users.
They're not faking the Referer, but they're certainly not sending it. So, again,
relying on that header for pretty much anything is not much of an idea.

jason




home help back first fref pref prev next nref lref last post