#29151 [Ana]: bugs.php.net fails to insert vote

From: Date: Wed, 04 Aug 2004 12:08:51 +0000
Subject: #29151 [Ana]: bugs.php.net fails to insert vote
References: 1  Groups: php.mirrors 
Request: Send a blank email to php-mirrors+get-25656@lists.php.net to get a copy of this message
ID: 29151 Updated by: jacques@php.net Reported By: fdsoft at pganet dot com Status: Analyzed Bug Type: Website problem Operating System: irrelevant PHP Version: Irrelevant New Comment: I'll commit the following patch later today if there are no problems with the suggested patch. It's based on a patch from phpweb. --jm cvs diff -u include/functions.inc vote.php Index: include/functions.inc =================================================================== RCS file: /repository/php-bugs-web/include/functions.inc,v retrieving revision 1.127 diff -u -r1.127 functions.inc --- include/functions.inc 13 Jul 2004 21:51:25 -0000 1.127 +++ include/functions.inc 4 Aug 2004 12:04:10 -0000 @@ -578,4 +578,35 @@ return array(" AND MATCH (bugdb.email,sdesc,ldesc) AGAINST ('" . addslashes($search) . "')", $ignored); } +/* Figure out which IP the user is coming from avoiding RFC 1918 space */ +function get_real_ip () { + $ip = false; + + /** + * User is behind a proxy and check that we discard RFC1918 IP + * addresses if they are behind a proxy then only figure out which + * IP belongs to the user. Might not need any more hacking if + * there is a squid reverse proxy infront of apache. + */ + if (!empty($HTTP_X_FORWARDED_FOR)) { + $ips = explode (", ", $HTTP_X_FORWARDED_FOR); + if ($ip) { array_unshift($ips, $ip); $ip = false; } + for ($i = 0; $i < count($ips); $i++) { + /** + * Skip RFC 1918 IP's 10.0.0.0/8, 172.16.0.0/12 and + * 192.168.0.0/16 -- jim kill me later with my regexp pattern + * below. + */ + if (!eregi ("^(10|172\.16|192\.168)\.", $ips[$i])) { + $ip = $ips[$i]; + break; + } + } + } + + /** + * Return with the found IP or the remote address + */ + return ($ip ? $ip : $REMOTE_ADDR); +} ?> Index: vote.php =================================================================== RCS file: /repository/php-bugs-web/vote.php,v retrieving revision 1.9 diff -u -r1.9 vote.php --- vote.php 23 Jan 2004 03:05:28 -0000 1.9 +++ vote.php 4 Aug 2004 12:04:10 -0000 @@ -21,7 +21,7 @@ or die("Unable to connect to SQL server."); @mysql_select_db("php3"); -$ip = ip2long($HTTP_X_FORWARDED_FOR ? $HTTP_X_FORWARDED_FOR : $REMOTE_ADDR); +$ip = ip2long(get_real_ip()); // TODO: check if ip address has been banned. hopefully this will // never need to be implemented. Previous Comments: ------------------------------------------------------------------------ [2004-07-26 22:00:01] jacques@php.net Looking into this atm. ------------------------------------------------------------------------ [2004-07-20 07:23:46] dave@php.net The offending code would be: $ip = ip2long($HTTP_X_FORWARDED_FOR ? $HTTP_X_FORWARDED_FOR : $REMOTE_ADDR); Normally a single proxy sits between the client and the server, giving a single IP address that ip2long() accepts, but if a connection is bounced through a chain of proxies, the X-Forwarded-For header will contain a list of those IPs in the form of: "X-Forwarded-For: <ip>[, <ip2>, ...]". eg. "X-Forwarded-For: 10.0.0.1, 10.0.0.2". This is probably why ip2long() is failing for these two people. Also, if you're not using a proxy that sets X-Forwarded-For, any client can set this header, making it untrustworthy. I could set my X-Forwarded-For: header to 'BLAH' and this script would fail. I suggest someone with php-bugs-web karma simply remove the X-Forwarded-For part and change the offending line to: $ip = ip2long($REMOTE_ADDR); If it becomes a problem with multiple people behind the same proxy, then you can add in exceptions for those people as the issue arises. ------------------------------------------------------------------------ [2004-07-20 06:49:24] mike at psy dot otago dot ac dot nz I'd like to vote on this as well instead of having to 'Me too!' but I can't vote :-) query INSERT INTO bugdb_votes (bug,ip,score,reproduced,tried,sameos,samever) VALUES(20720,,1,1,1,0,0); failed: You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near '1,1,1,0,0)' at line 1 ------------------------------------------------------------------------ [2004-07-14 15:55:14] fdsoft at pganet dot com Description: ------------ Trying to vote on a bug resulted in the following page: query INSERT INTO bugdb_votes (bug,ip,score,reproduced,tried,sameos,samever) VALUES(29149,,-2,1,1,0,0); failed: You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near '-2,1,1,0,0)' at line 1 I suspect the website code is trying to use $_SERVER["HTTP_X_FORWARDED_FOR"] which is set to the string "unknown" in my case, a common configuration option for the Squid web proxy. $_SERVER["REMOTE_ADDR"] would contain the correct IP address of my proxy. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=29151&edit=1

« previous php.mirrors (#25656) next »