OK - there is a LOT misinformation about referrers.

Started by Mumntette, October 16, 2012, 11:23:56 AM

Previous topic - Next topic

Mumntette

OK - there is a LOT misinformation about referrers.

What is a referrer?
The referrer, or HTTP referrer—also known by the common misspelling referer that occurs as an HTTP header field—identifies, from the point of view of an internet webpage or resource, the address of the webpage of the resource which links to it.

By checking the referrer, the new page can see where the request came from. Referrer logging is used to allow websites and web servers to identify where people are visiting them from, for promotional or security purposes.

Referrer is a popular tool to hxxp://www.baidu.com combat cross-site request forgery, but such security mechanisms do not work when the referrer is disabled. Referrer is widely used for statistical purposes.
Example 3.
What if our Google.com url links to someting external Page C. Click the link, the iframe now shows page C. What is the referrer for C?
Most browsers report that referrer is B (Google.com).

Example 4.
What if you nest iframes in Iframes etc.?
Well Always look at the page where the link is located. The closest containing page will always be the referrer for the link.
If you have nested iframes the referrer for the iframe is the closest containing iframe or page.

Gregg

baidu is so desperate they are spamming boards now? Too bad so sad ... not.
Practically all of china is not allowed to register here or post due to the volume of spam.
It's funny that great firewall of China can can keep you Chinese from seeing the pictures
of Tiananmen Square protests of 1989 but can not block your spam from leaving the country too.

No misinformation as far as I am concerned, referers aren't worth a shit as a "security mechanism," they are just a header that can be falsified and commonly are.

mario

Quote from: Gregg on October 16, 2012, 11:40:25 AM
It's funny that great firewall of China can can keep you Chinese from seeing the pictures
of Tiananmen Square protests of 1989 but can not block your spam from leaving the country too.

it is simple. Keep out everything they don't want, but "export" spam for profit.