tags:

views:

83

answers:

4

how do I spoof a referrer ?

originalsite.com has

header("Location: http://www.example.org");

I tried putting header("Location: http://www.destination.com"); in example.org

but checking the referer at destination.com, it shows originalsite.com as referer not example.org !

+2  A: 

You cannot, in an HTTP Response, instruct a client to send any specific HTTP header when it makes its next HTTP Request.

David Dorward
+1  A: 

"Referer" is a header sent by the web browser, and it's usually the last page the browser saw. You can't tell the browser what to show there, unless you own www.example.com and can set stuff up to bounce to you.

cHao
I own example.com, and put header("Location: www.destination.com");, however I checked destination.com and it shows that the referer is not example.com
Kim Jong Woo
To elaborate, what cHao was getting at is that you need a "bounce.php" page on example.com which would redirect the user. So something like example.com/bounce.php?site=destination.com all it does is do a redirect to the address in site, this would be a dynamic version. If it does not need to be dynamic, the just have bounce.php do a redirect to destination.com and be done with it.
Brad F Jacobs
how do I bounce it ? can you provide a sample code ?
Kim Jong Woo
ohh do you mean something like header("Location: $sitevar"); ?
Kim Jong Woo
premiso, http_referer still shows originalsite.com as refer, even though I bounced it off example.com using header("Location: $_GET['site']); by doing header("Location: http://www.example.com/?site="destination.com");
Kim Jong Woo
A: 

When you use header() in PHP with Location, it doesn't send any headers straight to where you set the Location. Instead, it sends headers back to the browser (the "Response" headers), then the browser makes another request to the indicated Location with a new set of "Request" headers. Only the user agent has control over the Request headers.

This means you'll have to make the request from the client perspective-- either with JavaScript, or more appropriately in this case, cURL (allows PHP to make additional HTTP requests from within a script).

EDIT: To spoof a referer with cURL, you would create a cURL resource then use this before executing the request:

curl_setopt($ch, CURLOPT_REFERER, 'fakereferer.org');
Daniel
yeah but this is done on the server side and doesn't redirect on client.
Kim Jong Woo
A: 

To elaborate on cHao's method:

example.com has a file on the server called bounce.php which has the following code:

<?php
// This is contained in bounce.php on example.com
$site = isset($_GET['site'])?$_GET['site']:null;
$safe_list = array("domain.com", "domain2.com"); // prevent others from using script for bad reasons

if (!empty($site) && in_array($site, $safe_list)) {
    header('Location: http://' . $site);
    exit;
}
?>

This is an example on usage on otherdomain.com

<?php
header('Location: http://example.com/bounce.php?site=domain.com');
exit;
?>

That should ensure the "bounce". But just know that if the user has the referrer turned off or set to something they wanted custom, this will not work for that situation.

The safe_list is to help prevent someone from using that page for their own purposes, basically only sites you say can be bounced to are allowed.

Update

Hopefully that is what you are looking for and I did not mis-interpret it.

Brad F Jacobs