Topic: confirm_refererer
Which are the consequences of the removal of the "confirm_refererer" of the files of the punbb?
I had some problems with the "refererer check" and that was my only solution.
You are not logged in. Please login or register.
PunBB Forums → PunBB 1.2 discussion → confirm_refererer
Which are the consequences of the removal of the "confirm_refererer" of the files of the punbb?
I had some problems with the "refererer check" and that was my only solution.
The confirm_referrer function is there for security purposes. I believe cross site scripting is merely one of the attacks you have made yourself open to by removing it.
The confirm_referrer function is there...
Cross site? Style php injection?
CSRF attacks.
Moved to PunBB Discussion
I don't think you will fall into a critical security hole, but the referer check makes things a bit more trick on the attacker side, so it's good to have it.
So i guess the answer is: none really. or... you will take one first ( very thin though ) defense down.
PS:Camarada, sem problema, esse inglês está bom.
pedrotuga: No. CSRF attacks are very real. Without the confirm_referrer check, I can make an administrator do things on a forum just by visiting a page I control (on any site).
PunBB Forums → PunBB 1.2 discussion → confirm_refererer
Powered by PunBB, supported by Informer Technologies, Inc.