停止欺骗表单提交 [英] Stop Spoofed Form Submissions

查看:177
本文介绍了停止欺骗表单提交的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

我有一个关于停止欺骗性表单提交的问题。如果通过使用 $ _ SERVER ['HTTP_REFERER'] 我只允许我的表单提交到我的网站提交的表单?这会有帮助吗?!感谢!

I have a question about stopping spoofed form submissions. How about if by using the $_SERVER['HTTP_REFERER'] I only allow submissions to my forms coming from my website? Would that help?! Thanks!

推荐答案

这将有所帮助,添加它相当容易,但它不会停止有针对性的攻击,毕竟你可以欺骗一个 HTTP_REFERER 头。

It would help, and it's fairly easy thing to add but it wont stop a targeted attack, after all you can spoof a HTTP_REFERER header.

有一点需要记住,客户端不需要发送 HTTP_REFERER ,所以如果头部丢失了,你可能想要允许提交。如果这是不可能的,然后检查 HTTP_REFERER 不会帮助你。

One thing to keep in mind is that a client is not required to send a HTTP_REFERER, so if the header is missing you might want to allow submissions anyway. If this is not possible, then checking HTTP_REFERER wont help you.

运行搜索CAPTCHA 完全自动的公共图灵测试来告诉计算机和人类的分离,这就是你真正想要的。

Run a search for CAPTCHA "Completely Automated Public Turing test to tell Computers and Humans Apart", this is what you're really looking for.

这篇关于停止欺骗表单提交的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆