04-09-2003, 09:12 AM
Lol, I've hit a brick wall.. Spookster has used is super powers to bypass my character limit settings from a form on his computer I presume.. Now I have set a letter limit in server side to stop him in his tracks no matter where the form is posted from but I'd still like to stop people (spookster first ;)) from being able to post to my processing page from their own forms.

HTTP_REFERER doesn't work.. So I've no idea how to do it. :confused:

PS: Thanks Spooks!/All hail spookster!

04-09-2003, 09:31 AM
lol Who me? :D Guess I will just have to find other holes to exploit. Muahahaha

04-09-2003, 09:33 AM
You'd better! It's good practice for me. :) Gunna tell me how to stop the forms?
Plus in a day or 2 I should have something resembling a forum for you to break :D..

04-09-2003, 10:46 AM

instantiate a session var on the form entry side and test for it on the receiving side.

04-09-2003, 10:51 AM
Originally posted by Ökii

instantiate a session var on the form entry side and test for it on the receiving side.

Already have a plan of attack for that defense too.

Go ahead make my day. Do ya feel lucky punk? Well do ya? :D

04-09-2003, 12:28 PM
yup - shouldn't be too tricky to get around that one - 'tis one more obstacle in the way of peeps like you though :D

short of using a flash input field or java based interface all the lil tricks I can think of have subtle workarounds -

though maybe md5(rand(0,100000)) and creating 32 hidden form fields to carry that hash - which then gets validated against a session held var would be annoying enough to stop spooksters from bothering.

or - the obvious 'input digits from generated image' ploy - would mean you'd need to manually construct a posting script each time - though even those images can be read and interpreted by GD at a push.

04-09-2003, 12:30 PM
Heheh, bring it on sporks! :)
I've disabled the char limit just so you can prove you are posting from your own form.
Thanks Ökii! :D

04-09-2003, 01:29 PM
Do you have any frames on your site? Anywhere. Doesn't need to be even related to your forum. If there is a frame on the domain you can use an IE exploit to submit data and you'll think it's from your own site.

04-09-2003, 01:38 PM
04-09-2003, 11:48 PM
It's for my shout box. :D .. And I do have frames. :confused: