# Flash to PHP security

**URL:** <https://forum.kirupa.com/t/flash-to-php-security/203810>\
**Category:** programming\
**Created:** [October 14, 2006, 10:05am UTC](https://forum.kirupa.com/t/flash-to-php-security/203810 "2006-10-14T10:05:38Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Laaf](https://avatars.discourse-cdn.com/v4/letter/l/7bcc69/32.png) [@Laaf](https://forum.kirupa.com/u/Laaf)\
**Post date:** [October 14, 2006, 10:05am UTC](https://forum.kirupa.com/t/flash-to-php-security/203810/1 "2006-10-14T10:05:38Z")

</div>

Hey all,

I have a problem with send Flash variables to PHP.  
I use the sendAndLoad (POST) command to send variables to PHP. Everything works fine, the PHP file stores certain variables in a database.

The problem is that if you decompile the swf you can have a look at the code and the variables, fake a post and send it to the PHP that stores the data.

What I need is something that verifies if the sent data comes from my SWF or from something else. I’ve been reading about HTTP\_REFERER, but that doesnt seem to be all that secure… any ideas?

hope you guys can help! thanks!
