


How to use PHP to obtain referer and determine the source to prevent illegal access
This article will introduce to you how to use PHP to obtain the referer to determine the source to prevent illegal access? It has certain reference value. Friends in need can refer to it. I hope it will be helpful to everyone.
The php code of download page down.php Now I found that if I open it directly with Thunder or Google Chrome, the downloaded file can be output, and it has no anti-leeching effect at all. Now I want to allow only those connected to my own site to use it directly. Those connected to other sites and those who directly enter this address will jump to the copy.htm page.
The $_SERVER["HTTP_REFERER"] predefined server variable in PHP can determine the source.
$_SESSION['HTTP_REFERER'] can obtain the source address of the previous connection of the current link, that is, the URL address of the previous page linked to the current page.
It is generally used to determine where the viewer clicked the link to jump to this page, that is, the so-called origin. It can also be used to prevent hotlinking by determining the origin.
For example:
1 2 3 4 5 6 7 8 |
|
Recently there is a project that needs to prevent users from illegally accessing a json page. The basic solution is to determine the source to restrict non-call access:
1 2 3 4 5 6 7 8 |
|
Putting this line of code at the top of the json data page can easily solve this problem.
Defects of this processing method: the normal data of the page can be obtained through forged sources.
Related code
The method of getting the source Url mainly uses the HTTP_REFERER function in the server variable. The code is pasted:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 |
|
php website Get the source Url The method mainly uses the HTTP_REFERER function in the server variable. The code is pasted:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
function
get_referer(){
$url
=
$_SERVER
[
"HTTP_REFERER"
];
//获取完整的来路URL
$str
=
str_replace
(“http:
//”,””,$url); //去掉http://
$strdomain
=
explode
(“/”,
$str
);
// 以“/”分开成数组
$domain
=
$strdomain
[0];
//取第一个“/”以前的字符
return
$domain
;
}
//对于百度、谷歌搜索引擎来路判断
function
get_seo(){
$s
= 0;
if
(
strstr
(get_referer(),’baidu.com’)){
$s
= 1;
}
else
if
(
strstr
(get_referer(),’google.com.hk’)){
$s
= 1;
}
return
$se
;
}
Copy after login
When processing a form, you have to consider Discuz has already judged the possibility of static submission by users based on formhash
Here I use another way to determine the origin of the page. Of course, this method can also be used to forge the origin of HTTP_REFERER
The second part is to solve the problem that header('location: in PHP cannot get HTTP_REFERER for the next page after jumping to the page. Here we can only add a link to the page and then use js to simulate clicking the link, so that the next page will definitely Received HTTP_REFERER. Keyword: document.getElementById('gourl').click();
Recommended learning: php video tutorial
The above is the detailed content of How to use PHP to obtain referer and determine the source to prevent illegal access. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics











PHP 8.4 brings several new features, security improvements, and performance improvements with healthy amounts of feature deprecations and removals. This guide explains how to install PHP 8.4 or upgrade to PHP 8.4 on Ubuntu, Debian, or their derivati

JWT is an open standard based on JSON, used to securely transmit information between parties, mainly for identity authentication and information exchange. 1. JWT consists of three parts: Header, Payload and Signature. 2. The working principle of JWT includes three steps: generating JWT, verifying JWT and parsing Payload. 3. When using JWT for authentication in PHP, JWT can be generated and verified, and user role and permission information can be included in advanced usage. 4. Common errors include signature verification failure, token expiration, and payload oversized. Debugging skills include using debugging tools and logging. 5. Performance optimization and best practices include using appropriate signature algorithms, setting validity periods reasonably,

This tutorial demonstrates how to efficiently process XML documents using PHP. XML (eXtensible Markup Language) is a versatile text-based markup language designed for both human readability and machine parsing. It's commonly used for data storage an

Static binding (static::) implements late static binding (LSB) in PHP, allowing calling classes to be referenced in static contexts rather than defining classes. 1) The parsing process is performed at runtime, 2) Look up the call class in the inheritance relationship, 3) It may bring performance overhead.

A string is a sequence of characters, including letters, numbers, and symbols. This tutorial will learn how to calculate the number of vowels in a given string in PHP using different methods. The vowels in English are a, e, i, o, u, and they can be uppercase or lowercase. What is a vowel? Vowels are alphabetic characters that represent a specific pronunciation. There are five vowels in English, including uppercase and lowercase: a, e, i, o, u Example 1 Input: String = "Tutorialspoint" Output: 6 explain The vowels in the string "Tutorialspoint" are u, o, i, a, o, i. There are 6 yuan in total

PHP and Python each have their own advantages, and choose according to project requirements. 1.PHP is suitable for web development, especially for rapid development and maintenance of websites. 2. Python is suitable for data science, machine learning and artificial intelligence, with concise syntax and suitable for beginners.

What are the magic methods of PHP? PHP's magic methods include: 1.\_\_construct, used to initialize objects; 2.\_\_destruct, used to clean up resources; 3.\_\_call, handle non-existent method calls; 4.\_\_get, implement dynamic attribute access; 5.\_\_set, implement dynamic attribute settings. These methods are automatically called in certain situations, improving code flexibility and efficiency.

PHP is a scripting language widely used on the server side, especially suitable for web development. 1.PHP can embed HTML, process HTTP requests and responses, and supports a variety of databases. 2.PHP is used to generate dynamic web content, process form data, access databases, etc., with strong community support and open source resources. 3. PHP is an interpreted language, and the execution process includes lexical analysis, grammatical analysis, compilation and execution. 4.PHP can be combined with MySQL for advanced applications such as user registration systems. 5. When debugging PHP, you can use functions such as error_reporting() and var_dump(). 6. Optimize PHP code to use caching mechanisms, optimize database queries and use built-in functions. 7
