Req #63076 [Com]: Force source IP on network operations

From: Date: Fri, 21 Apr 2023 05:49:35 +0000
Subject: Req #63076 [Com]: Force source IP on network operations
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-244240@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=63076&edit=1 ID: 63076 Comment by: bignewsvyres at gmail dot com Reported by: tonix at interazioni dot it Summary: Force source IP on network operations Status: Open Type: Feature/Change Request Package: Network related PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Techcutters is here to provide you with all popular options whether it is about tips for social media, blogs, and articles or news for sports fashion, tech, entertainment, and many more. More info:(https://techcutters.com)github.com Previous Comments: ------------------------------------------------------------------------ [2012-09-13 08:19:32] tonix at interazioni dot it bindto looks to be a programming option. I'm asking for a PHP directive, similar to OPEN_BASEDIR, which will force the bind address for any function opening/creating a socket or network connection. This should be imposed by the system manager, when there is a multidomain/multiIP apache. It would be useful to have something like: BIND_IP 'x.x.x.x' (specific IP do be used for binding) BIND_LISTEN (force use of IP on which the apache connection is received) ------------------------------------------------------------------------ [2012-09-13 01:09:38] aharvey@php.net You can already do this for any function that accepts a stream context via the bindto context option. Is there a specific case that isn't covered? ------------------------------------------------------------------------ [2012-09-12 20:08:00] tonix at interazioni dot it Description: ------------ It would nbe nice to have a new security feature in PHP. Actually, a web server receives connections from a specific IP/port, but any PHP script can use any available address on outgoing connections. This can be a security problem. It should be possible to 'force' PHP to open connections only with a spcific IP or with the listening IP.This helps to prevent such problems: * if you have internal interfaces in the same machine where you have public IPs, a web PHP application could try to use the internal address of the interface, exploring internal network (actually we avoid that thanks to FreeBSD jails). * if apache listens on a specific IP for a single domain, and listens on other IPs for others domains, it would be safe if each domain can use as source IP only the listening IP associated. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=63076&edit=1

« previous php.bugs (#244240) next »