Req #66676 [Opn->Fbk]: $_SERVER['REMOTE_ADDR'] insecure
| From: | requinix@php.net | Date: | Sun, 09 Feb 2014 06:34:59 +0000 |
| Subject: | Req #66676 [Opn->Fbk]: $_SERVER['REMOTE_ADDR'] insecure | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184224@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66676&edit=1
ID: 66676
Updated by: requinix@php.net
Reported by: hj at BridgeportContractor dot com
Summary: $_SERVER['REMOTE_ADDR'] insecure
-Status: Open
+Status: Feedback
Type: Feature/Change Request
Package: Apache related
Operating System: windows 7, x64 and *nix
PHP Version: 5.4.25
Block user comment: N
Private report: N
New Comment:
1. REMOTE_ADDR comes through CGI. PHP does not determine its value.
2. It does, in fact, come from "the TCP exchange" and not "the HTTP exchange".
3. I don't know where you're looking but *I* am seeing people confirm that it is safe. It
can be forged to varying degrees of usability, and that may be the untrustworthiness you've
heard about, but the value is inherently a valid IPv4/6 address.
So I'm going to mark this as needing feedback and you can continue looking into why you got
that in your log?
Previous Comments:
------------------------------------------------------------------------
[2014-02-09 06:12:32] hj at BridgeportContractor dot com
Description:
------------
REMOTE_ADDR is not to be trusted.
Can you get the server's IP from the tcp exchange rather than from the http exchange?
I recently logged '183.60..244.37' from $_SERVER['REMOTE_ADDR'] from an attack
http request on my hosing server. This is clearly not a valid IP address. A little research and I
have found that others too say to not trust REMOTE_ADDR from $_SERVER in php.
I think PHP needs a trustworthy replacement, as this is the only way to log http accesses.
See also: http://serverfault.com/questions/574239/double-dots-in-otherwise-valid-ip4-addreses-e-g-183-60-244-37/574245?noredirect=1#comment669478_574245
Thanks for all of your work guys.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66676&edit=1