Re: Referer (was Patches for wwwboard.pl)

daemon@ATHENA.MIT.EDU (Kevin Littlejohn)
Wed Oct 14 14:13:24 1998

Date: 	Wed, 14 Oct 1998 13:02:48 +1000
Reply-To: Kevin Littlejohn <darius@connect.com.au>
From: Kevin Littlejohn <darius@CONNECT.COM.AU>
In-Reply-To:  Your message of "Tue, 13 Oct 1998 10:26:48 -0400." 

>>> Lincoln Stein wrote
> The original article did suggest incorporating the IP address and a
> timestamp in the hash function.  The main point of the article was
> that using just the Referer field for security was a very bad idea.
> I sure hope this thread will be killed soon!

Um - sorry ;)

One comment I wanted to make re: web security - if you're relying on
the IP number of the machine requesting the file for any sort of security,
then you'll break your web site for anyone using multiple proxies.  In .au,
this is especially a problem, as we have some fairly large hierarchies
of proxy servers - for a lot of our users, a single web 'session' can
generate requests from multiple different boxes, as different proxies
react faster for each request.

Sorry to extend the thread, but people trying to tie web security down
to originator IP number is a pet hate of mine ;/

