Reverse Proxy Security

任晓磊 julyclyde at gmail.com
Fri Apr 23 07:46:33 MSD 2010


You may choose a unusual Header name.

On Fri, Apr 23, 2010 at 6:09 AM, karmaboy <nginx-forum at nginx.us> wrote:
> When using nginx as reverse proxy, to determine the actual client IP address I would need to rely on the X-Real-IP header. Since this is just an HTTP header than can be faked, is it possible for a visitor to include an X-Real-IP header value of their own, passing a fake IP to the back-end server? Does nginx always overwrite this value with the one it detects?
>
> Thx
>
> Posted at Nginx Forum: http://forum.nginx.org/read.php?2,78144,78144#msg-78144
>
>
> _______________________________________________
> nginx mailing list
> nginx at nginx.org
> http://nginx.org/mailman/listinfo/nginx
>



-- 
Ren Xiaolei



More information about the nginx mailing list