Security: Referrer - Get Articles by Richard Lowe

Get Articles
 
  

submit your own reprintable article

Article Categories

Accepting Credit Cards Online
Accounting and Book-Keeping
Advertising
Affiliate and Associate Programs
Articles and Article Promotion
Autoresponders and How To Use Them
Bonuses and Freebies
Branding
Business Ideas
Business Practice
Communication Skills
Competition and Your Competitors
Copywriting
Creativity and Ideas
Customer Service and Support
Domains and Domain Names
Due Diligence
E-Commerce
Ebooks and Ebook Writing
Education
Email List Building
Email Marketing
Ethics and Morals
Expert Status
Ezines and Email Newsletters
Family
Forums
Fraud and Scams
Goal Setting
Graphics and Graphic Design
Guarantees
Health
Internet Auctions
Internet Marketing
Investment and Investing
Job and Career
Joint Ventures
Lead Generation
Legislation and Legal Issues
Management and Best Practice
Motivation
Negotiation
Networking
News Releases and Public Relations
Niche Marketing
Outsourcing
Pay Per Click Search Engines
PC Security and Viruses
Pricing and Supply and Demand
Product Creation
Public Speaking
Publicity
Relationship Building
Reprint Rights
Revenue Generation
Search Engines and SEO
Site Stickiness - Getting Repeat Visitors
Software Reviews
Spam - Unsolicited Commercial Email
Statistics and Tracking
Testimonials
Time Management
Traffic Generation - Getting Hits
Travel
Viral Marketing
Web Hosting
Web Site Design
Working At Home - Starting Out
Blank Page
 
Google
 

> Get Articles > PC Security and Viruses > Security: Referrer

Security: Referrer


PDF icon Download as PDF

Richard Lowe
articlesinternet-tips.net

Internet Tips And Secrets
http://www.internet-tips.net


Copyright (C) Richard Lowe Jr. and Claudia Arevalo-Lowe, 1999-2001.

Permission is granted to reprint the following article as long as no

changes are made and the byline, copyright information, and the

resource box is included. Please let me know if you use this article

by sending an email to mailto:articlesinternet-tips.net



Article Title: Security: Referrer

Author: Richard Lowe, Jr.

Contact Author: mailto:articlesinternet-tips.net

Publishing Guidelines: May be freely published w/bylines

Web Address: http://www.internet-tips.net

Autoresponder Address: mailto:article-172internet-tips.net



If you are a webmaster, you will find that one of the most valuable things you can use is the referrer. On the other hand, if you are a surfer, you may want to disable this feature as it can be a security risk and a violation of your privacy.



What is this referrer thingie? Well, all web servers have the capability to create log files and virtually all web masters (at least those who know what they are doing) use these logs to determine how their web site is doing. The log files contain one line for each hit to the web site. The format and contents of the line vary from server to server (and webmasters can specify they want more or less information), but in general it has an incredible amount of information about that one hit.



Some of the information gathered for each hit to a web site includes (among other things):



- The requested file (for example, index.html)

- A status code indicating success or error (404 errors, for example)

- The browser type being used by the surfer (this is the agent name, and it can also be the name of a search engine spider or a spam harvester).

- The screen resolution of the surfer's monitor

- The date and time (locally to the server) of the hit

- The TCP/IP address of the surfer (yes, every web page that you have ever looked at has your TCP/IP recorded in a web server log file somewhere).

- The URL where the surfer came from



It's this last statistic that causes some concern. Oh, there is a minor issue in that your TCP/IP address is stored in the server logs when you access a page, but this is not very important. You see, these logs do not tend to last very long as they get very large extremely quickly. Many (if not most) web sites purge these as soon as statistics are gathered. Conceivably, of course, this could be of concern if an investigation were performed ... and these logs are looked at by webmasters for hacking attempts.



No, the important information is the referrer field. Why? Well, first there is the privacy question. If a webmaster knew your TCP/IP address (and he would have to know your address specifically, since this is the only thing relating you to the line in the log file - there is no name or email address stored there) he could get an idea of what you looked at before you came to his site. Thus, there is a remote chance that your privacy could be compromised ... a very remote chance since this is virtually never done by any webmaster.



The second, and very critical problem is a real security risk. You see, many websites allow you to log into their sites to personalize your experience. These sites allow you to enter personal data such as credit card information, social security numbers and other items into their database. Generally cookies are used to identify you as you move from page to page through the web site. Cookies are by far the best and preferred way to do this - it's called maintaining context. However, cookies are frowned upon my many surfers for various reasons (mostly blown out of proportion fears created by a press that feels it needs dangers and bad news to stay competitive).



Thus, some clever webmasters have come up with alternate ways to allow their web sites to know that "you are you" as you move around on their site. A very sloppy method consists of adding a username and password on to the end of each URL.



For example, suppose you log into a shopping site with a username and password like so:



URL: http://www.anyshoppingsite.com

Username: innocent

Password: naive



If you moved to a page called "toys.htm", the URL might become:



http://www.anyshoppingsite.com?u=innocent?p=naive



You see the problem? Not yet? Okay, there is no problem as you move around from page to page within the shopping site. The problem results when you surf to another page outside of the shopping site.



What happens? Well, if you surfed to another site from the page above, that URL complete with the username and password would be added to the server log files. Guess what, your username and password just got recorded in plain text somewhere completely unexpected.



So what's the problem really? Well, let's say you went to your shopping site, logged in and made some purchases. To make it simple for you, your credit card numbers are stored on the site and you can retrieve them at any time after you are logged in. Everything seems safe because you need a username and password to get in.



Now, when you are finished shopping you are supposed to log out. This would remove the username and password from the referrer. However, you don't do this and instead surf to another site. You leave your username and password in that webmasters log files. If that webmaster happens to check his log files he could get your username and password, log into your account and get your credit card numbers.



Are you alarmed yet?



Okay, how do you stop this from happening? It's relatively easy, actually. You get a product called AdSubtract and install it on your computer. By default this product will remove the referrer field as you surf around. You are now protected.



Oh yes, one side effect is you cannot just surf to that shopping site, since the login information is removed by AdSubtract. Fortunately, AdSubtract allows you to configure exceptions. All you need to do is enter the "filters" section, add your shopping site and specify to not remove the referrer.



And that, my friends, is how you protect yourself from one of the internet's biggest gaping security holes. I hope this has been of use to you.





NOTE: The following information must be included if you reprint this

article:

----------------------------------------------------------------------

Richard Lowe Jr. is the webmaster of Internet Tips And Secrets. This

website includes over 1,000 free articles to improve your internet

profits, enjoyment and knowledge.

Web Site Address: http://www.internet-tips.net

Weekly newsletter: http://www.internet-tips.net/joinlist.htm

Daily Tips: mailto:internet-tipsGetResponse.com



Claudia Arevalo-Lowe is the webmistress of Internet Tips And Secrets

and Surviving Asthma. Visit her site at http://survivingasthma.com



List of articles available for reprint: mailto:article-listinternet-tips.net





How useful did you find this article?

Not at all
A little
Averagely
Fairly
Very
 


This article can be downloaded freely from http://www.get-articles.com and used on your website or in your ezine so long as the author is credited and their resource box left intact. You should not change any links in the article, and where the article is used on a website it's links should be clickable. Please see our terms and conditions page for more information: http://www.get-articles.com/authors-publishers-terms.php
 

Get Articles


Top Articles

  • Stop Saving Money!
    By Leo J Quinn Jr
    Rating 138 / 195
  • The Top Ten Reasons For Being Honest
    By Monique Rider
    Rating 152 / 180
  • Top 10 Qualities of a Great Team Leader
    By Naseem Mariam
    Rating 143 / 180
  • 7 M's of Every Highly Effective Manager
    By Alonzie Scott
    Rating 124 / 175
  • Seven "Secrets/Tips" to Becoming a Millionaire
    By Craig Lock
    Rating 97 / 140
  • Five wonderful steps for good presentation skills:
    By Thomson Chemmanoor
    Rating 44 / 75
  • Do Pop-up Ads Work for Your Site?
    By Brian Su
    Rating 41 / 70
  • How to get your audience involved in your PowerPoint presentation:
    By Thomson Chemmanoor
    Rating 27 / 70
  • TOP TEN TIPS FOR PRESCRIPTION SWIMMING GOGGLES
    By Danielle Ross
    Rating 53 / 65
  • Ten Steps to a Power-Packed, Persuasive Proposal
    By Linda Elizabeth Alexander
    Rating 46 / 65
  • Insider Rollout Secrets Review
    By Alex Poole
    Rating 52 / 55
  • The 7 Signs of a Scam
    By Sharon Davis
    Rating 42 / 50
  • How to write a communication plan
    By Matt Eliason
    Rating 38 / 50
  • The MSN Ranking Code Loophole
    By Chris Rempel and Dave Kelly
    Rating 38 / 50
  • 12-Step Foolproof Sales Letter Template
    By David Frey
    Rating 41 / 45
  • Tips For Non-Sexist Writing
    By Tanja Rosteck
    Rating 35 / 45
  • Preventing Fraud On Your Website
    By Aaron Turpen
    Rating 32 / 40
  • Useless Resume Objectives
    By Rita Fisher, CPRW
    Rating 10 / 40
  • Hacker Prevention Techniques
    By Aaron Turpen
    Rating 30 / 35
  • 6 Steps to Great Customer Service
    By Aaron Turpen
    Rating 25 / 35

    May 26, 2012 © www.Get-Articles.com. All Rights Reserved.