Jump to content
  • Advertisement
Sign in to follow this  
geo2004

[web] Composite Control wierd UrlReferrer.Host

This topic is 3409 days old which is more than the 365 day threshold we allow for new replies. Please post a new topic.

If you intended to correct an error in the post then please contact us.

Recommended Posts

I have a ASP .Net 2.0 Composite Control that I created at work. It is a simple control used to gather information like name, address, email, phone. We host this form on several different pages throughout our domain. We want to track how much traffic each form gets, so I get the domain from Context.Request.UrlReferrer.Host, and I get the page from Context.Request.UrlReferrer.AbsolutePath. With this information we can track exactly how much traffic each form gets. We noticed today that we have some info in our database that came from one of these forms, but the domain and page are ones we've never heard of before (I know its from code executed on this form because we insert a certain 'created by' parameter for that row in the database). I'm trying to figure out how this is possible? Is it possible for a bot or something to fill out the info on the page, and somehow trick it to think its being referred from a different page? Or is someone actually able to host this form on their site? I'm not a security guru by any means, but both of these seem very unlikely. Does anyone know how something like this might be done? Note: The dll for the control is kept in the /bin folder of our site, not the GAC, if that matters at all. Thanks, Geo

Share this post


Link to post
Share on other sites
Advertisement
Bots can edit what their referral is and it is very possible the form can be hosted elsewhere.

Share this post


Link to post
Share on other sites
Sign in to follow this  

  • Advertisement
×

Important Information

By using GameDev.net, you agree to our community Guidelines, Terms of Use, and Privacy Policy.

We are the game development community.

Whether you are an indie, hobbyist, AAA developer, or just trying to learn, GameDev.net is the place for you to learn, share, and connect with the games industry. Learn more About Us or sign up!

Sign me up!