Re: Getting a client's IP address

From: Date: Tue, 16 Oct 2001 11:31:59 +0000
Subject: Re: Getting a client's IP address
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-71198@lists.php.net to get a copy of this message
On Tuesday 16 October 2001 13:00, Jon Haworth wrote: > A better method is to use: > > if (getenv(HTTP_X_FORWARDED_FOR)) { > > $ip=getenv(HTTP_X_FORWARDED_FOR); > } else { > $ip=getenv(REMOTE_ADDR); > } > > This way you don't pick up the proxy address. If you then want to > only allow access from certain IPs you can use something like: There's a problem with this aproach. Clients can easily fake HTTP_X_FORWARDED_FOR headers by just sending the requested ip address in them. So they'll be identified as a proxy, while they are just clients sending out fake headers. Of course this doesn't matters if the computers are on a known intranet with a known a proxy or without a proxy. Arpi > > if (!strstr($ip, "192.168.0.")) { > header("HTTP/1.0 403 Forbidden"); exit; > } > > this would only allow people with 192.168.0.x IPs (common for LANs) > to access your page. >

« previous php.general (#71198) next »