You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Samy Kamkar网站返回不同load.js的实现原理及PHP检测请求来源的可行性

How Samy Kamkar Serves Different load.js Versions (And How PHP Can Do This)

Let's walk through exactly how this trick works, and yes—PHP absolutely has the tools to detect where a request is coming from.

The Core Idea: Detecting Request Context

This whole setup hinges on telling two types of requests apart:

  • Direct requests to load.js (like typing the URL into your address bar, or loading it from an external site)
  • Requests that originate from within the samy.pl website itself—especially when the browser's dev tools are detached.

Key Signals to Check

  1. HTTP Referer Header
    When you load a script from a webpage, your browser sends a Referer header that tells the server which page initiated the request. For requests from samy.pl, this header will point to a page on that domain. But if you hit the script URL directly, the Referer will be empty or from an unrelated source.

  2. Dev Tools Detachment Quirk
    Some browsers isolate the dev tools' request context when it's attached to the main window. Detaching the console makes it inherit the main page's context, so the Referer header gets sent correctly—hence why you need to detach it to get the right script.

PHP Can Absolutely Handle This

PHP gives you access to all incoming request headers via the $_SERVER superglobal. Here's a simplified example of how you'd replicate this behavior:

<?php
// Grab the Referer header if it exists
$referer = $_SERVER['HTTP_REFERER'] ?? '';

// Check if the request came from samy.pl
if (str_contains($referer, 'samy.pl')) {
    // Send the Easter egg #2 version with obfuscated code
    header('Content-Type: application/javascript');
    echo "// No source for you! Easter egg #2\n";
    echo "/* Your obfuscated JavaScript goes here */";
} else {
    // Send the Easter egg #9 version for direct requests
    header('Content-Type: application/javascript');
    echo "// No source for you! Easter egg #9";
}
?>

Samy probably added extra checks to make this more robust, like:

  • Verifying the User-Agent to spot browser dev tool contexts
  • Using the Origin header as a fallback for stricter CSP scenarios
  • Checking for session cookies to ensure the request is tied to an active visit on his site

A Quick Note on Reliability

While the Referer header can be spoofed, it's reliable enough for distinguishing legitimate browser requests from direct URL hits. The dev tools detachment requirement is just a quirk of how some browsers handle request contexts for attached vs. detached dev tools.


内容的提问来源于stack exchange,提问作者hamburger

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:13:50