Re: Accessed based off of IP...

From: Chris Hope (blackhole_at_electrictoolbox.com)
Date: 04/19/04


Date: Mon, 19 Apr 2004 16:48:21 +1200

Dan Tripp wrote:

>>>There are certain scripts that I have that only I want to run, both from
>>>home and sometimes work. If I add something like this (below) to the
>>>scripts, will this keep out unauthorized use (if the scripts are found
>>>somehow), or can the REMOTE_ADDR be easily spoofed ?
>>
>>
>> You can send TCP/IP packets with fake return addresses fairly easily. But
>> to take advantage of it in an attack against a web server is hard, I
>> believe, as the HTTP response would get routed to the real address.
>>
>
> Just kinda thinking out loud... by why not limit access to the directory
> your scripts are in with .htaccess or IIS's authentication? That'd
> probably be a bit more secure than relying upon the REMOTE_ADDR.

Not an answer to your solution, but a suggestion that instead of writing out
a meta tag refresh you might want to do this instead:

header("Location: /index.php");
exit;

Chris

-- 
Chris Hope
The Electric Toolbox Ltd
http://www.electrictoolbox.com/


Relevant Pages

  • Ralphf@aol.com is a hideous, flaccid, grandmother-injecting crack clown 0.94435441493988
    ... Otherwise the candle in Marilyn's frog might attack some angry ... It can strangely like distant and dines our durable, ... Chris, still receiving, explains almost simply, as the ... Allen and Jon covered the strange islands above fresh enigma. ...
    (rec.pets.cats.anecdotes)
  • Re: Open Ports
    ... [root@chris chris]# netstat -pnlut ... ode -icon knode.png -miniicon knode.png ... Connection closed by foreign host. ... Failure To Connect To Web Server ...
    (comp.os.linux.security)
  • Re: You wont find Chris X talking about this
    ... >> A little lenient Chris, ... such a terrible crime. ... >> If that attack would have had Chinese teenagers attacking a white guy we ... People comment about the weather Chris, this was a murder by a gang, surely ...
    (uk.politics.misc)
  • Re: Wince WebServer
    ... Microsoft Corporation ... Whether or not it will suit your needs better than ISAPI only you know. ... Chris Tacke - Embedded MVP ... Microsoft Web server in it? ...
    (microsoft.public.windowsce.app.development)
  • Re: What did you expect at lvl 60 ? (other content)
    ... >> I didn't attack you if I remember correctly. ... Actually Roger, when I read Chris' first reply, I assumed his "I don't mean ... case your suggestion would stand here stronger. ... >>> I didn't realize I WAS suggesting anything to my boss. ...
    (alt.games.warcraft)