Hi Lars,

Am Sonntag, den 25.10.2015, 15:14 +0100 schrieb Lars Kruse:
> Hi Marcus,
> 
> 
> Am Sun, 25 Oct 2015 10:46:40 +0100
> schrieb Marcus Schopen <li...@localguru.de>:
> 
> 
> > Hmmm ... in my setup the rewriterule doesn't hide/remove the referer.
> 
> Shame on me - you are right. I am not sure, how/if/when it worked before.
> I apologize for my bad advise regarding apache's rewrite - please ignore it.

I did some tests: if the dereferrer rewrite rules are setup on a ssl
host, the referrer will removed when forwarding to a non SSL address. An
HTTP request to an HTTP request will have a referrer, so will HTTPS to
HTTPS (even cross domain). HTTPS sites will not send referrers to HTTP.
So apache rewrite rules do not hide in all cases. I think a script which
reloads itself and then forward to the external address is necessary.
Any good known? I found this one:

https://github.com/papoms/php-dereferer-cloaking-script

Ciao!




------------------------------------------------------------------------------
_______________________________________________
Moin-user mailing list
Moin-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/moin-user

Reply via email to