note 24738 added to function.intval

From: Date: Tue, 27 Aug 2002 13:49:10 +0000
Subject: note 24738 added to function.intval
Groups: php.notes 
Request: Send a blank email to php-notes+get-35733@lists.php.net to get a copy of this message
To check whever a hostname (as returned when parsing an URL) is a deprecated IPv4 address given as a single int that should better be changed to the canonical IP4 address, don't use intval() or is_int() directly. Better use a more secure code that will detect these possible "aliases" of an IPv4 address (converting them to a canonical IPv4 form), and unset all invalid hostnames: if (preg_match('/^-?\d+$/', $host)) { if (strcmp(long2ip($host)).'', $host)!=0) unset($host); //invalid! else $host = ip2long(long2ip($host))); //canonicalize! } else if (preg_match('/\.-?\d+$/', $host) && !preg_match( '/((0|[12]([0-9][0-9]?)?|[3-9][0-9]?)\.){3}'. '(0|[12]([0-9][0-9]?)?|[3-9][0-9]?)/', $host) unset($host); //invalid! The remaining host name is either a valid canonical (dotted) IPv4 address, a simple hostname, or a domain name. Next you may check whever a valid host does not match a reserved or local hostname, such as '/^(0|10|127|169\.254|172\.(1[6-9]|2[0-9]|3[01])|192\.168|'. '2[2-5][0-9])(\.[0-9]+)*$/' which matches addresses in the following set: - private "anycast" addresses: 0/8 (1 class A subnet); - private "local host" addresses: 127/8 (1 class B subnet); - private "autoconf" addresses: 169.254/16 (1 class B subnet); - private "local net" addresses: 10/8 (1 class A subnet), 172.16/20 (31 class B subnets), 192.168/16 (256 class C subnets); - special "multicast" addresses: 224/4 (all class D); - private "broadcast" addresses: 240/4 (all class E). -- http://www.php.net/manual/en/function.intval.php http://master.php.net/manage/user-notes.php?action=edit+24738 http://master.php.net/manage/user-notes.php?action=delete+24738 http://master.php.net/manage/user-notes.php?action=reject+24738

« previous php.notes (#35733) next »