note 40811 deleted from function.getenv by bjori
| From: | bjori@php.net | Date: | Sat, 25 Mar 2006 11:00:12 +0000 |
| Subject: | note 40811 deleted from function.getenv by bjori | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-106579@lists.php.net to get a copy of this message | ||
Note Submitter: daniele_dll at yahoo dot it
----
referred to info at barclaey nospam dot com post
getIP function is written bad! If a user, that is behind a proxy in his lan, connect to a web site,
and someone use this function to get ip, and proxy send HTTP_X_FORWARDED_FOR or HTTP_CLIENT_IP
header your script will have a LAN ip, totally unuseful over internet! So, i think, that a good
solution can use all headers! For example:
<?php
function getIP() {
$tmparr = array();
$tmparr[] = $_SERVER['REMOTE_ADDR'];
if (isset($_SERVER['HTTP_X_FORWARDED_FOR'])) {
$tmparr += explode(',',$_SERVER['HTTP_X_FORWARDED_FOR']);
}
return $tmparr;
}
print_r(getIP());
?>
this code contains a list of ips...the last is client ip, the second is first proxy, the second
before the last is the second proxy...ecc ecc ecc...the first is ip client or last proxy used.
Naturally if any proxy is used there is only an element...ip of the client :)
(HTTP_X_FORWARDED_FOR contains a comma separated list of clients IP - Proxy can be configure to use
other proxies so, if proxy is configured to use HTTP_X_FORWARDED_FOR, will send a comma separated
list of ips)
I've haven't used into script HTTP_CLIENT_IP because i don't know this header, i
haven't found it in any rfc however it can be added without any difficult
PS: pls do not use getenv to read standard vars :) getenv is a function so is very very very slow
compare to a simply array read :)
PS2: sorry for my english :)
bye