in reply to Another way to find http referrer
Isn't it easier to configure the HTTP server to only accept https connections?
REMOTE_ADDR can be faked, but is harder to do. But that doesn't give you any information whether the request was using https or not.
As a general advice, don't roll your own security. Leave it to the experts, and do it at the right layer.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Another way to find http referrer
by Anonymous Monk on Feb 28, 2012 at 11:05 UTC | |
|
Re^2: Another way to find http referrer
by Anonymous Monk on Feb 27, 2012 at 22:57 UTC | |
by aaron_baugher (Curate) on Feb 27, 2012 at 23:27 UTC | |
by Anonymous Monk on Feb 27, 2012 at 23:48 UTC | |
by JavaFan (Canon) on Feb 27, 2012 at 23:01 UTC | |
by Anonymous Monk on Feb 27, 2012 at 23:17 UTC | |
by JavaFan (Canon) on Feb 27, 2012 at 23:31 UTC |