Req #66676 [Opn->Fbk]: $_SERVER['REMOTE_ADDR'] insecure

From: Date: Sun, 09 Feb 2014 06:34:59 +0000
Subject: Req #66676 [Opn->Fbk]: $_SERVER['REMOTE_ADDR'] insecure
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184224@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66676&edit=1 ID: 66676 Updated by: requinix@php.net Reported by: hj at BridgeportContractor dot com Summary: $_SERVER['REMOTE_ADDR'] insecure -Status: Open +Status: Feedback Type: Feature/Change Request Package: Apache related Operating System: windows 7, x64 and *nix PHP Version: 5.4.25 Block user comment: N Private report: N New Comment: 1. REMOTE_ADDR comes through CGI. PHP does not determine its value. 2. It does, in fact, come from "the TCP exchange" and not "the HTTP exchange". 3. I don't know where you're looking but *I* am seeing people confirm that it is safe. It can be forged to varying degrees of usability, and that may be the untrustworthiness you've heard about, but the value is inherently a valid IPv4/6 address. So I'm going to mark this as needing feedback and you can continue looking into why you got that in your log? Previous Comments: ------------------------------------------------------------------------ [2014-02-09 06:12:32] hj at BridgeportContractor dot com Description: ------------ REMOTE_ADDR is not to be trusted. Can you get the server's IP from the tcp exchange rather than from the http exchange? I recently logged '183.60..244.37' from $_SERVER['REMOTE_ADDR'] from an attack http request on my hosing server. This is clearly not a valid IP address. A little research and I have found that others too say to not trust REMOTE_ADDR from $_SERVER in php. I think PHP needs a trustworthy replacement, as this is the only way to log http accesses. See also: http://serverfault.com/questions/574239/double-dots-in-otherwise-valid-ip4-addreses-e-g-183-60-244-37/574245?noredirect=1#comment669478_574245 Thanks for all of your work guys. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66676&edit=1

« previous php.bugs (#184224) next »