Re: [PHP] POST security

2003-09-05 Thread Dan Anderson
Be careful about hidden variables and form variables. A clever user can create a new form with custom edited fields and ACTION="yoursite.com" For instance, if you keep a hidden variable: It's not very hard for a computer saavy person to create a new form where it says: And circumvent your

Re: [PHP] POST security

2003-09-05 Thread Chris Shiflett
--- bob pilly <[EMAIL PROTECTED]> wrote: > Is there any security issues with passing data via the > POST method from a webserver to a different webserver > running ssl. There are always security concerns, regardless of your approach. Nothing is perfect. However, sending data over an SSL connection

[PHP] POST security

2003-09-05 Thread bob pilly
Hi all, i know this isnt strictly a php question but thought you would be a good group to ask because of your experience. Is there any security issues with passing data via the POST method from a webserver to a different webserver running ssl. For example: webserver1 and then just using on