From: Arlen Cuss Date: 2008-03-30T17:30:29+09:00 Subject: Re: remote ip address ------=_Part_1204_30652540.1206865827408 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Content-Disposition: inline Hi, On Sun, Mar 30, 2008 at 7:24 PM, Ben Aroia wrote: > echo " >
"; > ?> > and then a > ip = cgi['ip'] in the ruby script. > This is dangerous to rely on. From a security point of a view (why do you want their IP anyway? question #1.), anyone could just submit a different `ip' value and you'd record that. See take Martin's advice as is: CGI.new.remote_addr will return the address without it being submitted via the PHP script, hence this line of `attack' is eliminated. Cheers, Arlen. ------=_Part_1204_30652540.1206865827408--