Is this safe? (.htaccess)

Discussion in 'Apache' started by yang9, Aug 10, 2008.

  1. #1
    I am currently using this to block everyone except when referred by my website. I know it is possible to spoof the http_referer but are there any alternative ways to overcome the spoofing? Or is there any other ways which would be more secure?

    RewriteEngine On
    RewriteCond %{REQUEST_FILENAME} .*avi$|.*mkv$|.*wmv$|.*zip$|[NC]
    RewriteCond %{HTTP_REFERER} !domain.com [NC]
    RewriteRule (.*) /denied.html
     
    yang9, Aug 10, 2008 IP
  2. jayshah

    jayshah Peon

    Messages:
    1,126
    Likes Received:
    68
    Best Answers:
    1
    Trophy Points:
    0
    #2
    You're not checking for the www. prefix.

    And there's no way to protect yourself against Referer spoofing.

    Jay
     
    jayshah, Aug 11, 2008 IP