Hi,

On Wed, 2003-03-19 at 22:28, Philarmon wrote:

> > All security measures needs to happen on the server, not from what the
> users
> > web browser gives you.
> 
> And how to do something like that on the server ? Is there a tutorial
> somewhere about this or something ? A few words about that would be great !
> :)

Perhaps you could generate a cookie when they fist enter your site and
then check that that cookie is valid when retrieving the content. If
then they don't have the cookie set you would know that they have linked
to the page directly rather than from following a link on your site.

The cookie would have to be some sort of random identifier that you also
stored on the web server somewhere so that you could validate the cookie
was authentic.

Regards,

AW


-- 
Abdul-Wahid Paterson

Lintrix Networking & Communications ltd.
Web: http://www.lintrix.net/
Tel: +44 7801 070621
Email/Jabber: [EMAIL PROTECTED]
--------------------------------------------------------------------
Web-Hosting  |  Development  |  Security  |  Consultancy  |  Domains
--------------------------------------------------------------------

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to