Welcome! Log In Create A New Profile

Advanced

RE: GeoIP FirstNonPrivateXForwardedForIP

Lukas Tribus
June 16, 2014 03:14AM
Hi,



> Thanks for your reply.
>
> I have already tried
> http://nginx.org/en/docs/http/ngx_http_geoip_module.html#geoip_proxy
>
> But this needs a list of subnets / networks to be whitelisted first as a
> trusted source. I do not (Can not) have a list of such networks as they can
> be intermediate proxy of any company. Eg : Google chrome on smartphone uses
> Google compression proxy in between before reaching the actual server where
> website is hosted. Opera mini also does the same and similarly don't know
> who all does it. So I can not have a list of all trusted networks.

You cannot trust X-F-F headers of untrusted third party networks and proxies,
otherwise everyone can spoof whatever remote IP they want.

Don't do this.



Lukas


_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

GeoIP FirstNonPrivateXForwardedForIP

Keyur June 12, 2014 12:36PM

RE: GeoIP FirstNonPrivateXForwardedForIP

Lukas Tribus June 12, 2014 01:12PM

Re: RE: GeoIP FirstNonPrivateXForwardedForIP

Keyur June 16, 2014 01:17AM

RE: GeoIP FirstNonPrivateXForwardedForIP

Lukas Tribus June 16, 2014 03:14AM

Re: RE: GeoIP FirstNonPrivateXForwardedForIP

Keyur June 16, 2014 03:19AM

Re: RE: GeoIP FirstNonPrivateXForwardedForIP

Keyur June 23, 2014 02:57AM

Re: RE: GeoIP FirstNonPrivateXForwardedForIP

Jonathan Matthews June 23, 2014 06:32AM

Re: RE: GeoIP FirstNonPrivateXForwardedForIP

Keyur June 23, 2014 07:05AM

Re: RE: GeoIP FirstNonPrivateXForwardedForIP

Steve Wilson June 23, 2014 07:18AM

RE: GeoIP FirstNonPrivateXForwardedForIP

Lukas Tribus June 23, 2014 08:32AM

Re: RE: GeoIP FirstNonPrivateXForwardedForIP

wandenberg July 31, 2014 10:13PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 314
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready