Re: Getting a client's IP address
| From: | Tamas Arpad | Date: | Tue, 16 Oct 2001 11:31:59 +0000 |
| Subject: | Re: Getting a client's IP address | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-71198@lists.php.net to get a copy of this message | ||
On Tuesday 16 October 2001 13:00, Jon Haworth wrote:
> A better method is to use:
>
> if (getenv(HTTP_X_FORWARDED_FOR)) {
>
> $ip=getenv(HTTP_X_FORWARDED_FOR);
> } else {
> $ip=getenv(REMOTE_ADDR);
> }
>
> This way you don't pick up the proxy address. If you then want to
> only allow access from certain IPs you can use something like:
There's a problem with this aproach. Clients can easily fake
HTTP_X_FORWARDED_FOR headers by just sending the requested ip address
in them. So they'll be identified as a proxy, while they are just
clients sending out fake headers. Of course this doesn't matters if
the computers are on a known intranet with a known a proxy or without
a proxy.
Arpi
>
> if (!strstr($ip, "192.168.0.")) {
> header("HTTP/1.0 403 Forbidden"); exit;
> }
>
> this would only allow people with 192.168.0.x IPs (common for LANs)
> to access your page.
>