Not so much, because I can view the source of your original form, find all the hidden fields and their values and add them to my spoofed form.


This is very difficult to do!!!!.


Would sessions help?  Not allow access to the action page if a session is not defined?  Much beyond that I'm not sure what is practical.

Confidentiality Notice:  This message including any
attachments is for the sole use of the intended
recipient(s) and may contain confidential and privileged
information. Any unauthorized review, use, disclosure or
distribution is prohibited. If you are not the
intended recipient, please contact the sender and
delete any copies of this message.
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Reply via email to