Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7629735
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 31, 20262026-05-31T05:54:44+00:00 2026-05-31T05:54:44+00:00

What is the best way to prevent host redirection? For example, say I have

  • 0

What is the best way to prevent host redirection?

For example, say I have some pseudo code like this:

string result = downloadStr("http://mywebsite.com/login.php?pass=whatever&username=whatever");
if(result == "true")
    return success_login;
else
    return failed_login;

I could easily just go and edit my ‘hosts’ file to redirect ‘mywebsite.com’ to my localhost, and always have it return ‘true’. Was this question not asked before because it is not a problem with security?

The best way I could think of would be doing something like this:

string ip = get_website_ip("http://mywebsite.com/");
if(ip != "216.250.121.107")
{
    //Host redirection detected.
}
else
{
    //It's all good.
}
  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-31T05:54:46+00:00Added an answer on May 31, 2026 at 5:54 am

    Generally speaking your entire technique of licensing (presumably) is flawed. You are right, someone can easily modify the hosts file and make that return true. Even if you changed it to the direct IP address, they can modify their firewall (and other things) to return a true value for this request as well.

    The better way of doing this is to not do it over an unencrypted HTTP request at all. Use an encrypted request to an IP address, and make sure you client can reliably authenticate your licensing server is who it says it is.

    An easy solution is to setup an SSL sertificate on your HTTP server. Then make this request over HTTPS, and verify the server in the HTTPS request. This way, you don’t even need to bother worrying if they tamper with the host file, since it will still not verify the SSL request.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

the best way to explain is with example so: this is the model public
The best way I can think of to ask this is by example... In
The best way of describing this is I have a table of people with
I am maintaining some code which looks something like this. It's a Windows service
hi sirs what's the best way to prevent google from showing of a folder
So, what is the best way to prevent an XSRF attack for a GAE
In PHP, I know that using parameterized queries is the best way to prevent
What is the best way to ensure service robustness to prevent a service becoming
What's the best way to prevent a dictionary attack? I've thought up several implementations
I need the best way to prevent any access to doc files when it

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.