RE: HTTPS redirections



Just be aware, that the referer can be forged fairly easily - don't rely on
it for any kind of security or authentication.

Basically, never trust the client (in this case, the browser).


Scott

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx] On
Behalf Of Jason Ross
Sent: Saturday, 25 August 2007 7:13 AM
To: anthony@xxxxxxxxxxxx
Cc: security-basics@xxxxxxxxxxxxxxxxx
Subject: Re: HTTPS redirections

On 8/24/07, anthony@xxxxxxxxxxxx <anthony@xxxxxxxxxxxx> wrote:
I have noticed how some websites only allow access to a particular
page if a link within the page has been 'clicked' ie. user cannot
paste link address in browser bar to get to desired page.
For security purposes I would like to create a script and achieve
similar results.

I believe that (at least one way) this is done is by checking the
referer header. In PHP this can be accessed via the predefined
variable: $_SERVER['HTTP_REFERER'], other languages should have
similar methods of obtaining this.

AFAIK, there is not a difference between HTTP and HTTPS as far as
this method is concerned.

--
Jason



Relevant Pages

  • [NEWS] Transparent Cache Engine and Content Engine TCP Relay Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The default configuration of the proxy ... The following Cisco Cache Engine and Content Engine products are affected ... of supported protocols such as FTP and HTTPS. ...
    (Securiteam)
  • Re: is HTTPS crackable
    ... (willing to question HTTPS protocal security prior to questioning ... OWA55/Kiosk security), not necessary Microsoft's strategy. ... > public Internet access by a kiosk, ... > about downloading and installing the self-signed certificate. ...
    (microsoft.public.inetserver.iis.security)
  • [fw-wiz] Help- Nat-t
    ... Security of HTTPS ... > Is there some possibility of a MITM attack? ... HTTPS relies on SSL / TLS. ...
    (Firewall-Wizards)
  • RE: SSL Reverse Proxy
    ... you could also use Squid in httpd accelerator mode. ... the communications between ISA and the backend servers are https ... > recognized corporate security certification track, ... This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization ...
    (Security-Basics)
  • Re: Security and Outlook over HTTP
    ... Outlook uses RPC over HTTPS. ... The security is the same as you ... would get with a secure web page, one who's address begins with HTTPS ... articles had me set the security with basic authentication. ...
    (microsoft.public.windows.server.sbs)