A fair security measure is to insist that your members have
cookies enabled to view the site. Use a combo of .htaccess and
cookies to verify members on login. As far as I know, there isn't
really a way to stop spoofers when your only validation is through
reading the Referrer. Not an expert, just my experiences.
|