Re: voting script
| From: | Roland Witvoet | Date: | Sat, 05 Aug 2000 02:35:57 +0000 |
| Subject: | Re: voting script | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-10231@lists.php.net to get a copy of this message | ||
charette@sneezy.org wrote:
> Roland wrote:
> >The only easy way to eliminate cheating is to log the ip-addresses :(
>
> If you'd review the archives you'd find that this is absolutely _not_ the way to
> eliminate cheating, but is an excellent way to stop _legitimate_ voting. Check your HTTP server logs
> someday - you may be surprised to find that half your traffic comes from 10 or 20 IP addresses - all
> proxies for a few big ISPs. IPs are generally not a good way to identify people.
IP address works through proxies and firewall, only not through routers using ip-masquerading (their
function is to hide your real ip address :( )
Please note that $REMOTE_ADDR indeed does provide the IP address of the proxy, so you should not
(only) use that but:
if (getenv("HTTP_X_FORWARDED_FOR"))
{ $ip=getenv("HTTP_X_FORWARDED_FOR");
} else
{ $ip=getenv("REMOTE_ADDR");
}
(see http://www.php.net/manual/function.getenv.php)
This might solve the problem for proxies that do cause problems? Although I really don't know
what HTTP_X_FORWARDED means....
I myself experience that HTTP_CLIENT_IP should be used instead of it so the above script is WRONG!!.
When accessing the web through a proxy server this shows my IP address while REMOTE_ADDR displays
the address of the proxy server. Maybe REMOTE_ADDR and HTTP_CLIENT_IP are proxy specific?
A word of warning: pages generated as a result of a form that gets it's data (method=get) are
supposed to be static pages. The pages may (and will) get cached by proxies and some other programs
(netscape and IE don't but netsonic does)
The problem is not using the IP address, the problem is getting the real IP address (users behind a
IP masquerading router are even impossible to trace).
(I thought we were going off topic so much that I posted a question also in a new thread called
"Real IP address?" so keep an eye on that one..)
We're getting awfully off topic, but anyway...
Links that change data on the server should never be used in the "get" way. A link to an
url like "http://website.com/page.php?action=delete"
might seem very attractive to use, but is a bad thing to use. This page can get in some cache and a
request of this page might give the cached page instead of contacting the server which was intended
to happen. Even more
dangerous, this page might be requested by some read ahead program (like netsonic, which gets the
pages before the user really requests the and thus improving access time) so the server might think
the user has clicked the link while he/she actually didn't do (yet). I know of a dutch
bookstore that made this mistake, resulting in a shopping cart containing all
books available :(
So make sure voting is done by a form that posts its data (method=post) This will prevent any
problems with proxies and other caching.