Re: Filter by HTTP_REFERER

2011-11-02 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Pid, On 11/2/11 4:24 AM, Pid * wrote: > It'll still be fragile and open to exploitation. An AJAX call can > any request headers it likes. You be better off using > authentication if you want anything more than a casual defence. +1 - -chris -BEG

Re: Filter by HTTP_REFERER

2011-11-02 Thread André Warnier
Casper Wandahl Schmidt wrote: Den 02-11-2011 10:50, André Warnier skrev: André Warnier wrote: Casper Wandahl Schmidt wrote: Den 02-11-2011 10:17, André Warnier skrev: Pid * wrote: On 31 Oct 2011, at 18:25, Christopher Schultz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Richa

Re: Filter by HTTP_REFERER

2011-11-02 Thread Casper Wandahl Schmidt
Den 02-11-2011 10:50, André Warnier skrev: André Warnier wrote: Casper Wandahl Schmidt wrote: Den 02-11-2011 10:17, André Warnier skrev: Pid * wrote: On 31 Oct 2011, at 18:25, Christopher Schultz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Richardo, On 10/31/2011 12:33 PM, R

Re: Filter by HTTP_REFERER

2011-11-02 Thread André Warnier
André Warnier wrote: Casper Wandahl Schmidt wrote: Den 02-11-2011 10:17, André Warnier skrev: Pid * wrote: On 31 Oct 2011, at 18:25, Christopher Schultz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Richardo, On 10/31/2011 12:33 PM, Ricardo Bayley wrote: You are right. What I in

Re: Filter by HTTP_REFERER

2011-11-02 Thread Casper Schmidt
2011/11/2 André Warnier > Casper Wandahl Schmidt wrote: > >> >> >> Den 02-11-2011 10:17, André Warnier skrev: >> >>> Pid * wrote: >>> On 31 Oct 2011, at 18:25, Christopher Schultz wrote: -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Richardo, > > On

Re: Filter by HTTP_REFERER

2011-11-02 Thread André Warnier
Casper Wandahl Schmidt wrote: Den 02-11-2011 10:17, André Warnier skrev: Pid * wrote: On 31 Oct 2011, at 18:25, Christopher Schultz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Richardo, On 10/31/2011 12:33 PM, Ricardo Bayley wrote: You are right. What I intend to do is prevent

Re: Filter by HTTP_REFERER

2011-11-02 Thread Casper Wandahl Schmidt
Den 02-11-2011 10:17, André Warnier skrev: Pid * wrote: On 31 Oct 2011, at 18:25, Christopher Schultz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Richardo, On 10/31/2011 12:33 PM, Ricardo Bayley wrote: You are right. What I intend to do is prevent hot linking. We get what you a

Re: Filter by HTTP_REFERER

2011-11-02 Thread André Warnier
Pid * wrote: On 31 Oct 2011, at 18:25, Christopher Schultz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Richardo, On 10/31/2011 12:33 PM, Ricardo Bayley wrote: You are right. What I intend to do is prevent hot linking. We get what you are trying to do: you'll just have to write you

Re: Filter by HTTP_REFERER

2011-11-02 Thread Pid *
On 31 Oct 2011, at 18:25, Christopher Schultz wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Richardo, > > On 10/31/2011 12:33 PM, Ricardo Bayley wrote: >> You are right. What I intend to do is prevent hot linking. > > We get what you are trying to do: you'll just have to write your

Re: Filter by HTTP_REFERER

2011-10-31 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Richardo, On 10/31/2011 12:33 PM, Ricardo Bayley wrote: > You are right. What I intend to do is prevent hot linking. We get what you are trying to do: you'll just have to write your own code to do it. Tomcat ships with a Filter called RequestFilter t

Re: Filter by HTTP_REFERER

2011-10-31 Thread Ricardo Bayley
You are right. What I intend to do is prevent hot linking. My webapp, is working as a REST webservice. So I would like to have tomcat reply only when requests come from specific sites. thanks 2011/10/31 André Warnier > Ricardo Bayley wrote: > >> Hi folks, >> >> I am trying to filter access to

Re: Filter by HTTP_REFERER

2011-10-31 Thread André Warnier
Ricardo Bayley wrote: Hi folks, I am trying to filter access to my webapp by the HTTP_REFERER I thought this could be achieved with the Valve Componenent using the Remote Host Filter such as I am not have in success. Can this be achieved or should I use Apache httpd to proxy requests? What

Re: Filter by HTTP_REFERER

2011-10-31 Thread Konstantin Kolinko
2011/10/31 Ricardo Bayley : > Hi folks, > > I am trying to filter access to my webapp by the HTTP_REFERER > I thought this could be achieved with the Valve Componenent using the > Remote Host Filter such as No. This filter has different purpose (you have read the docs?). You can always write your

Filter by HTTP_REFERER

2011-10-31 Thread Ricardo Bayley
Hi folks, I am trying to filter access to my webapp by the HTTP_REFERER I thought this could be achieved with the Valve Componenent using the Remote Host Filter such as I am not have in success. Can this be achieved or should I use Apache httpd to proxy requests? Best regards Ricardo