As far as I know you a malicious site can't fake a referer header* (unless maybe if you allow cross-site XMLHTTP - but all modern browsers prohibit that - right?)
--MidLifeXis
In reply to Re^2: Is your web application really secure? ("CSRF")
by MidLifeXis
in thread Is your web application really secure? ("CSRF")
by tinita
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |