获取客户端IP ,HTTP_CLIENT_IP 是一个骗局吗?
获取客户端IP,很多代码都会拿 HTTP_CLIENT_IP
的值,其次拿 HTTP_X_FORWARDED_FOR
,最后是 REMOTE_ADDR
。
关于这个的讨论见:http://www.douban.com/group/topic/27482290/
比较的好的获取客户端IP和验证IP代码是怎样的
以下内容是听取答案后的总结
1.HTTP_CLIENT_IP
头是有的,只是未成标准,不一定服务器都实现了。
2.HTTP_X_FORWARDED_FOR
是有标准定义,用来识别经过HTTP代理
后的客户端IP地址,格式:clientip,proxy1,proxy2
。详细解释见 http://zh.wikipedia.org/wiki/X-Forwarded-For
3.REMOTE_ADDR
是可靠的, 它是最后一个跟你的服务器握手的IP
,可能是用户的代理服务器,也可能是自己的反向代理。
关于伪造:HTTP_*
头都很容易伪造。例如使用火狐插件伪造x-forwarded_for
IP为8.8.8.8
,此时清掉cookie再访问http://www.58.com, 它会以为你是8.8.8.8
来的。参考: sf上另一个关于伪造IP的问题
一段不错的获取IP代码:<code>function get_client_ip() { foreach (array( 'HTTP_CLIENT_IP', 'HTTP_X_FORWARDED_FOR', 'HTTP_X_FORWARDED', 'HTTP_X_CLUSTER_CLIENT_IP', 'HTTP_FORWARDED_FOR', 'HTTP_FORWARDED', 'REMOTE_ADDR') as $key) { if (array_key_exists($key, $_SERVER)) { foreach (explode(',', $_SERVER[$key]) as $ip) { $ip = trim($ip); //会过滤掉保留地址和私有地址段的IP,例如 127.0.0.1会被过滤 //也可以修改成正则验证IP if ((bool) filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_IPV4 | FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE)) { return $ip; } } } } return null; } </code>Copy after loginCopy after login参考 @joyqi 的思路,有些情况可以考虑只获取
REMOTE_ADDR
(PS:一般不会这样做)
回复内容:
获取客户端IP,很多代码都会拿 HTTP_CLIENT_IP
的值,其次拿 HTTP_X_FORWARDED_FOR
,最后是 REMOTE_ADDR
。
关于这个的讨论见:http://www.douban.com/group/topic/27482290/
比较的好的获取客户端IP和验证IP代码是怎样的
以下内容是听取答案后的总结
1.HTTP_CLIENT_IP
头是有的,只是未成标准,不一定服务器都实现了。
2.HTTP_X_FORWARDED_FOR
是有标准定义,用来识别经过HTTP代理
后的客户端IP地址,格式:clientip,proxy1,proxy2
。详细解释见 http://zh.wikipedia.org/wiki/X-Forwarded-For
3.REMOTE_ADDR
是可靠的, 它是最后一个跟你的服务器握手的IP
,可能是用户的代理服务器,也可能是自己的反向代理。
关于伪造:HTTP_*
头都很容易伪造。例如使用火狐插件伪造x-forwarded_for
IP为8.8.8.8
,此时清掉cookie再访问http://www.58.com, 它会以为你是8.8.8.8
来的。参考: sf上另一个关于伪造IP的问题
一段不错的获取IP代码:<code>function get_client_ip() { foreach (array( 'HTTP_CLIENT_IP', 'HTTP_X_FORWARDED_FOR', 'HTTP_X_FORWARDED', 'HTTP_X_CLUSTER_CLIENT_IP', 'HTTP_FORWARDED_FOR', 'HTTP_FORWARDED', 'REMOTE_ADDR') as $key) { if (array_key_exists($key, $_SERVER)) { foreach (explode(',', $_SERVER[$key]) as $ip) { $ip = trim($ip); //会过滤掉保留地址和私有地址段的IP,例如 127.0.0.1会被过滤 //也可以修改成正则验证IP if ((bool) filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_IPV4 | FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE)) { return $ip; } } } } return null; } </code>Copy after loginCopy after login参考 @joyqi 的思路,有些情况可以考虑只获取
REMOTE_ADDR
(PS:一般不会这样做)
REMOTE_ADDR
不可以显式的伪造,虽然可以通过代理将ip地址隐藏,但是这个地址仍然具有参考价值,因为它就是与你的服务器实际连接的ip地址。
相比之下,前两种ip地址都可以通过http header来伪造,但并不意味着它们一无是处。生产环境中很多服务器隐藏在负载均衡节点后面,你通过REMOTE_ADDR
只能获取到负载均衡节点的ip地址,一般的负载均衡节点会把前端实际的ip地址通过HTTP_CLIENT_IP
或者HTTP_X_FORWARDED_FOR
这两种http头传递过来
后端再去读取这个值就是真实可信的,因为它是负载均衡节点告诉你的而不是客户端。但当你的服务器直接暴露在客户端前面的时候,请不要信任这两种读取方法,只需要读取REMOTE_ADDR
就行了

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

PHP 8.4 brings several new features, security improvements, and performance improvements with healthy amounts of feature deprecations and removals. This guide explains how to install PHP 8.4 or upgrade to PHP 8.4 on Ubuntu, Debian, or their derivati

Visual Studio Code, also known as VS Code, is a free source code editor — or integrated development environment (IDE) — available for all major operating systems. With a large collection of extensions for many programming languages, VS Code can be c

JWT is an open standard based on JSON, used to securely transmit information between parties, mainly for identity authentication and information exchange. 1. JWT consists of three parts: Header, Payload and Signature. 2. The working principle of JWT includes three steps: generating JWT, verifying JWT and parsing Payload. 3. When using JWT for authentication in PHP, JWT can be generated and verified, and user role and permission information can be included in advanced usage. 4. Common errors include signature verification failure, token expiration, and payload oversized. Debugging skills include using debugging tools and logging. 5. Performance optimization and best practices include using appropriate signature algorithms, setting validity periods reasonably,

A string is a sequence of characters, including letters, numbers, and symbols. This tutorial will learn how to calculate the number of vowels in a given string in PHP using different methods. The vowels in English are a, e, i, o, u, and they can be uppercase or lowercase. What is a vowel? Vowels are alphabetic characters that represent a specific pronunciation. There are five vowels in English, including uppercase and lowercase: a, e, i, o, u Example 1 Input: String = "Tutorialspoint" Output: 6 explain The vowels in the string "Tutorialspoint" are u, o, i, a, o, i. There are 6 yuan in total

This tutorial demonstrates how to efficiently process XML documents using PHP. XML (eXtensible Markup Language) is a versatile text-based markup language designed for both human readability and machine parsing. It's commonly used for data storage an

Static binding (static::) implements late static binding (LSB) in PHP, allowing calling classes to be referenced in static contexts rather than defining classes. 1) The parsing process is performed at runtime, 2) Look up the call class in the inheritance relationship, 3) It may bring performance overhead.

What are the magic methods of PHP? PHP's magic methods include: 1.\_\_construct, used to initialize objects; 2.\_\_destruct, used to clean up resources; 3.\_\_call, handle non-existent method calls; 4.\_\_get, implement dynamic attribute access; 5.\_\_set, implement dynamic attribute settings. These methods are automatically called in certain situations, improving code flexibility and efficiency.

PHP and Python each have their own advantages, and choose according to project requirements. 1.PHP is suitable for web development, especially for rapid development and maintenance of websites. 2. Python is suitable for data science, machine learning and artificial intelligence, with concise syntax and suitable for beginners.
