note 40811 deleted from function.getenv by bjori

From: Date: Sat, 25 Mar 2006 11:00:12 +0000
Subject: note 40811 deleted from function.getenv by bjori
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-106579@lists.php.net to get a copy of this message
Note Submitter: daniele_dll at yahoo dot it ---- referred to info at barclaey nospam dot com post getIP function is written bad! If a user, that is behind a proxy in his lan, connect to a web site, and someone use this function to get ip, and proxy send HTTP_X_FORWARDED_FOR or HTTP_CLIENT_IP header your script will have a LAN ip, totally unuseful over internet! So, i think, that a good solution can use all headers! For example: <?php function getIP() { $tmparr = array(); $tmparr[] = $_SERVER['REMOTE_ADDR']; if (isset($_SERVER['HTTP_X_FORWARDED_FOR'])) { $tmparr += explode(',',$_SERVER['HTTP_X_FORWARDED_FOR']); } return $tmparr; } print_r(getIP()); ?> this code contains a list of ips...the last is client ip, the second is first proxy, the second before the last is the second proxy...ecc ecc ecc...the first is ip client or last proxy used. Naturally if any proxy is used there is only an element...ip of the client :) (HTTP_X_FORWARDED_FOR contains a comma separated list of clients IP - Proxy can be configure to use other proxies so, if proxy is configured to use HTTP_X_FORWARDED_FOR, will send a comma separated list of ips) I've haven't used into script HTTP_CLIENT_IP because i don't know this header, i haven't found it in any rfc however it can be added without any difficult PS: pls do not use getenv to read standard vars :) getenv is a function so is very very very slow compare to a simply array read :) PS2: sorry for my english :) bye

« previous php.notes (#106579) next »