It would help, and it's fairly easy thing to add but it wont stop a targeted attack, after all you can spoof a HTTP_REFERER
header.
One thing to keep in mind is that a client is not required to send a HTTP_REFERER
, so if the header is missing you might want to allow submissions anyway. If this is not possible, then checking HTTP_REFERER
wont help you.
Run a search for CAPTCHA "Completely Automated Public Turing test to tell Computers and Humans Apart", this is what you're really looking for.
与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…