$_SERVER['HTTP_REFERER'] doesnt work with firewall on?

Posted on 2005-03-07
Medium Priority
Last Modified: 2008-02-01

hi. my pages doesnt work on some of my client's computer. the page depends on $_SERVER['HTTP_REFERER'] variable. those who were not able to see the page propperly reported taht they have firewall on.

is $_SERVER['HTTP_REFERER'] against firewall?
is there a way to resolve this..?
Question by:sutejok
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 11

Accepted Solution

matt_mcswain earned 1000 total points
ID: 13483525
No, not always. It's totally dependent on the client and can be easily spoofed w/ about 3 lines of code useing curl; among other ways. Sorry, you just can't depend on it.
LVL 32

Assisted Solution

ldbkutty earned 1000 total points
ID: 13483821
>> is there a way to resolve this..?

Due to the "untrustable" nature of HTTP_REFERER, I'd use $_SESSION or $_POST or $_GET variable to store the filename $_SERVER["PHP_SELF"] and check it in the next page.. Like this :

my_page1.php :

$_SESSION["referal"] = $_SERVER["PHP_SELF"];
// blah..blah..

referred_page.php :

if(!isset($_SESSION["referal"])) {
 // Session not set, re-direct the user...
else {
 // User came through the my_page1.php. so allow him..

Author Comment

ID: 13526109
thx guys

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article discusses four methods for overlaying images in a container on a web page
Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
The viewer will learn how to dynamically set the form action using jQuery.
The viewer will learn how to create and use a small PHP class to apply a watermark to an image. This video shows the viewer the setup for the PHP watermark as well as important coding language. Continue to Part 2 to learn the core code used in creat…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question