Curl the file to issue the request fake_ip.php:
Code
| The code is as follows |
Copy Code |
|
<?php
$ch = Curl_init ();
$url = "http://localhost/target_ip.php";
$header = Array (
' client-ip:58.68.44.61 ',
' x-forwarded-for:58.68.44.61 ',
);
curl_setopt ($ch, Curlopt_url, $url);
curl_setopt ($ch, Curlopt_httpheader, $header);
curl_setopt ($ch, curlopt_returntransfer,true);
$page _content = curl_exec ($ch);
Curl_close ($ch);
echo $page _content;
?>
The requested target file target_ip.php:
Code
<?php
echo getenv (' http_client_ip ');
echo getenv (' http_x_forwarded_for ');
echo getenv (' remote_addr ');
?> |
The IP print order in the target file target_ip is the IP capture sequence of many open source systems at present
Visit fake_ip.php and see the results:
58.68.44.61
58.68.44.61
127.0.0.1
Instance
Curl is really tough and can forge IP and source.
1.php request 2.php.
| The code is as follows |
Copy Code |
|
1.php Code:
$ch = Curl_init ();
curl_setopt ($ch, Curlopt_url, "http://localhost/2.php");
curl_setopt ($ch, Curlopt_httpheader, Array (' x-forwarded-for:8.8.8.8 ', ' client-ip:8.8.8.8 ')); Constructing IP
curl_setopt ($ch, Curlopt_referer, "http://www.111cn.net/"); Structural antecedents
curl_setopt ($ch, Curlopt_header, 1);
$out = curl_exec ($ch);
Curl_close ($ch);
The 2.php code is as follows:
function Getclientip () {
if (!empty ($_server["HTTP_CLIENT_IP"]))
$ip = $_server["Http_client_ip"];
else if (!empty ($_server["http_x_forwarded_for"]))
$ip = $_server["Http_x_forwarded_for"];
else if (!empty ($_server["REMOTE_ADDR"]))
$ip = $_server["REMOTE_ADDR"];
Else
$ip = "Err";
return $IP;
}
echo "IP:". Getclientip (). "";
echo "Referer:". $_server["Http_referer"];
|
Forgery success, this is not to "brush the ticket" friends to provide a good exchange of IP program!!