Samy Kamkar网站返回不同load.js的实现原理及PHP检测请求来源的可行性
load.js Versions (And How PHP Can Do This) Let's walk through exactly how this trick works, and yes—PHP absolutely has the tools to detect where a request is coming from.
The Core Idea: Detecting Request Context
This whole setup hinges on telling two types of requests apart:
- Direct requests to
load.js(like typing the URL into your address bar, or loading it from an external site) - Requests that originate from within the
samy.plwebsite itself—especially when the browser's dev tools are detached.
Key Signals to Check
HTTP Referer Header
When you load a script from a webpage, your browser sends aRefererheader that tells the server which page initiated the request. For requests fromsamy.pl, this header will point to a page on that domain. But if you hit the script URL directly, theRefererwill be empty or from an unrelated source.Dev Tools Detachment Quirk
Some browsers isolate the dev tools' request context when it's attached to the main window. Detaching the console makes it inherit the main page's context, so theRefererheader gets sent correctly—hence why you need to detach it to get the right script.
PHP Can Absolutely Handle This
PHP gives you access to all incoming request headers via the $_SERVER superglobal. Here's a simplified example of how you'd replicate this behavior:
<?php // Grab the Referer header if it exists $referer = $_SERVER['HTTP_REFERER'] ?? ''; // Check if the request came from samy.pl if (str_contains($referer, 'samy.pl')) { // Send the Easter egg #2 version with obfuscated code header('Content-Type: application/javascript'); echo "// No source for you! Easter egg #2\n"; echo "/* Your obfuscated JavaScript goes here */"; } else { // Send the Easter egg #9 version for direct requests header('Content-Type: application/javascript'); echo "// No source for you! Easter egg #9"; } ?>
Samy probably added extra checks to make this more robust, like:
- Verifying the
User-Agentto spot browser dev tool contexts - Using the
Originheader as a fallback for stricter CSP scenarios - Checking for session cookies to ensure the request is tied to an active visit on his site
A Quick Note on Reliability
While the Referer header can be spoofed, it's reliable enough for distinguishing legitimate browser requests from direct URL hits. The dev tools detachment requirement is just a quirk of how some browsers handle request contexts for attached vs. detached dev tools.
内容的提问来源于stack exchange,提问作者hamburger

