02.11.2014 Views

untangling_the_web

untangling_the_web

untangling_the_web

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

DID: 4046925<br />

UNCLA551FIEDHFOR OFflClaliL USE ONLY<br />

Disable or Defeat <strong>the</strong> HTTP-Referrer<br />

The "http referrer" variable (often misspelled "referer"184) may be a serious<br />

concern. This variable lets a site you are visiting know which site you just came from<br />

(which site referred you to <strong>the</strong>m). Usually, <strong>the</strong> value of <strong>the</strong> "referrer" field is <strong>the</strong> uri of<br />

<strong>the</strong> page you last visited. The problem is that <strong>the</strong> http-referrer variable gives out<br />

more information. If you use a search engine to find a site and <strong>the</strong>n click on that<br />

site, <strong>the</strong> http-referrer will provide <strong>the</strong> entire query you used to find <strong>the</strong> site!<br />

Fur<strong>the</strong>rmore, it is possible that o<strong>the</strong>r sensitive types of information, such as<br />

username, password, email address, or even a credit card number, could be sent as<br />

part of an http-referrer variable.l'"<br />

There are ways around this problem. Here are three solutions:<br />

1. Don't click on a link from a search engine; instead right-click on <strong>the</strong> link and<br />

select Copy Link Location (Mozilla) or Copy Shortcut (IE6); paste <strong>the</strong> link in <strong>the</strong><br />

address window, and go to <strong>the</strong> link from <strong>the</strong> new browser window. Your query will<br />

not be provided. Remember: you must copy <strong>the</strong> link to <strong>the</strong> address bar; it is not<br />

sufficient to right-click and "open in new window" or "open in new tab."<br />

2. Use a browser-based service that blocks <strong>the</strong> http-referrer, such as Webwasher<br />

or Guidescope, both of which are free to individual users, or any number of products<br />

that can be purchased for this purpose.<br />

Webwasher 186<br />

http://www.cyberguard.com/products/<strong>web</strong>washer/<strong>web</strong>washerproducts/classic/index.html<br />

Guidescope<br />

http://www.guidescope.com/home/<br />

3. Disable <strong>the</strong> http-referrer in Netscape 7 and Firefox (you cannot do this in<br />

Internet Explorer). In <strong>the</strong> Address/Location bar, type about:config and find<br />

network. http.sendRefererHeader. This variable can be set to 0, 1, or 2:<br />

2-default; send referrer for all requests<br />

1-do not send referrer for images<br />

184 The actual "referrer" code uses <strong>the</strong> incorrect spelling "referer," which may say something about <strong>the</strong><br />

spelling skills of programmers.<br />

185 For an excellent overview of <strong>the</strong> legitimate use of and problems with <strong>the</strong> http-referrer, see, Lincoln<br />

D. Stein, "Referer Refresher, " New Architect, September 1998,<br />

(14 November 2006).<br />

186 Webwasher Classic is now owned by Cyberguard and is still free, though <strong>the</strong> company does<br />

request a donation.<br />

UNCLA55IFIEDI'ifiOR OFflOlaliL USE ONLY 539

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!