|
|
Joined: Apr 2002
Posts: 206
Member
|
|
Member
Joined: Apr 2002
Posts: 206 |
I recently had to disable this because we had a user who we need to be able to use the forums have referrer errors pop up until I disabled the check.
So, what's the drawback in me doing this? Some kinda of security hole?
|
|
|
|
|
Joined: Feb 2001
Posts: 2,268
Junior Member
|
|
Junior Member
Joined: Feb 2001
Posts: 2,268 |
It's possible that someone could spam your board from another domain, but I've not had it happen to me since Ihad to disable it on my site.
Many new firewall programs (Zone Alarm, McAffee, etc) remove the referer information from http requests as a "privacy" feature. Nothing but marketting BS -very little, if anything, can be gained by watching where people are coming from to get to your site.
|
|
|
|
|
Joined: Apr 2002
Posts: 206
Member
|
|
Member
Joined: Apr 2002
Posts: 206 |
OK... So, they could spam in a way they could not before?
|
|
|
|
|
Joined: Feb 2001
Posts: 2,268
Junior Member
|
|
Junior Member
Joined: Feb 2001
Posts: 2,268 |
Yes. If referrer is enabled then the referrer information in the http header would have to match your domain. With the referrer check disabled the http packets could come from any site.
Keep in mind that using a referrer check is a deterrent, and not a guarantee. You could still get spammed by another domain even if you have the referrer check enabled because the referrer information in an http header can be spoofed.
So far I haven't had a problem with someone spamming my board. Since Threads does a pretty good job of recording the source IP address that was used for a post most people don't bother. You would have to use some pretty sophisticated scripting routines to make a spam post and spoof the IP address that you are coming from. Not impossible, but beyond the means of the average "script kiddy" hacker.
The best security advice that I have is for you to force people to give you a valid email address so they can get their initial password, and allow mods and admins to see IP addresses. You could even block email registrations from free sites like hotmail and yahoo, and any site that acts as an autonomizer. People are less likely to get out of line if they have to give you an email address from their ISP or a work email server...
|
|
|
|
|
Joined: May 2002
Posts: 153
Member
|
|
Member
Joined: May 2002
Posts: 153 |
"The best security advice that I have is for you to force people to give you a valid email address so they can get their initial password, and allow mods and admins to see IP addresses. You could even block email registrations from free sites like hotmail and yahoo, and any site that acts as an autonomizer. People are less likely to get out of line if they have to give you an email address from their ISP or a work email server..."
That makes a lot of sense but people can also change the email after they register... there should be a verification when the emails are changed too
|
|
|
|
|
Joined: Feb 2001
Posts: 2,268
Junior Member
|
|
Junior Member
Joined: Feb 2001
Posts: 2,268 |
Take a look at your users from the admin panel. The database stores the email that they registered with (it's their "original email"). 
|
|
|
|
|
Joined: Apr 2002
Posts: 1,768
Addict
|
|
Addict
Joined: Apr 2002
Posts: 1,768 |
[]people can also change the email after they register... there should be a verification when the emails are changed too[/] That's a good point. I just started a thread in the Feedback board on this subject.
|
|
|
Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.
Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
|
|
Posts: 808
Joined: July 2001
|
|
|
Forums63
Topics37,583
Posts293,955
Members13,825
| |
Most Online151,614 Nov 14th, 2025
|
|
Currently Online 2100
Topics Created 0
Posts Made 0
Users Online 0
Birthdays 7
|
|
|
|