RE: [PHP] Getting a client's IP address
| From: | Jon Haworth | Date: | Tue, 16 Oct 2001 11:38:11 +0000 |
| Subject: | RE: [PHP] Getting a client's IP address | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-71200@lists.php.net to get a copy of this message | ||
On 16 October, Tamas Arpad is alleged to have said:
> On Tuesday 16 October 2001 13:00, Jon Haworth wrote:
> > A better method is to use:
> >
> > if (getenv(HTTP_X_FORWARDED_FOR)) {
> >
> > $ip=getenv(HTTP_X_FORWARDED_FOR);
> > } else {
> > $ip=getenv(REMOTE_ADDR);
> > }
> >
> > This way you don't pick up the proxy address. If you then want to
> > only allow access from certain IPs you can use something like:
>
> There's a problem with this aproach. Clients can easily fake
> HTTP_X_FORWARDED_FOR headers by just sending the requested ip address
> in them. So they'll be identified as a proxy, while they are just
> clients sending out fake headers. Of course this doesn't matters if
> the computers are on a known intranet with a known a proxy or without
> a proxy.
Well, there's problems with IP addresses full stop :-)
If you need to authenticate people there are much better ways of doing it.
If you're only using them to display different sorts of content, personally
I'd do that from a user database anyway (that way the content follows the
user wherever they log on from).
Cheers
Jon
**********************************************************************
'The information included in this Email is of a confidential nature and is
intended only for the addressee. If you are not the intended addressee,
any disclosure, copying or distribution by you is prohibited and may be
unlawful. Disclosure to any party other than the addressee, whether
inadvertent or otherwise is not intended to waive privilege or confidentiality'
**********************************************************************