note 24738 added to function.intval
| From: | php-general at lists dot php dot net | Date: | Tue, 27 Aug 2002 13:49:10 +0000 |
| Subject: | note 24738 added to function.intval | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-35733@lists.php.net to get a copy of this message | ||
To check whever a hostname (as returned when parsing an URL) is a deprecated IPv4 address given as a
single int that should better be changed to the canonical IP4 address, don't use intval() or
is_int() directly. Better use a more secure code that will detect these possible "aliases"
of an IPv4 address (converting them to a canonical IPv4 form), and unset all invalid hostnames:
if (preg_match('/^-?\d+$/', $host)) {
if (strcmp(long2ip($host)).'', $host)!=0) unset($host); //invalid!
else $host = ip2long(long2ip($host))); //canonicalize!
} else if (preg_match('/\.-?\d+$/', $host) && !preg_match(
'/((0|[12]([0-9][0-9]?)?|[3-9][0-9]?)\.){3}'.
'(0|[12]([0-9][0-9]?)?|[3-9][0-9]?)/', $host)
unset($host); //invalid!
The remaining host name is either a valid canonical (dotted) IPv4 address, a simple hostname, or a
domain name.
Next you may check whever a valid host does not match a reserved or local hostname, such as
'/^(0|10|127|169\.254|172\.(1[6-9]|2[0-9]|3[01])|192\.168|'.
'2[2-5][0-9])(\.[0-9]+)*$/'
which matches addresses in the following set:
- private "anycast" addresses: 0/8 (1 class A subnet);
- private "local host" addresses: 127/8 (1 class B subnet);
- private "autoconf" addresses: 169.254/16 (1 class B subnet);
- private "local net" addresses: 10/8 (1 class A subnet), 172.16/20 (31 class B subnets),
192.168/16 (256 class C subnets);
- special "multicast" addresses: 224/4 (all class D);
- private "broadcast" addresses: 240/4 (all class E).
--
http://www.php.net/manual/en/function.intval.php
http://master.php.net/manage/user-notes.php?action=edit+24738
http://master.php.net/manage/user-notes.php?action=delete+24738
http://master.php.net/manage/user-notes.php?action=reject+24738