note 40807 added to function.gethostbyaddr
| From: | MagicalTuxatFF dot ST at rn2 dot php dot net | Date: | Mon, 15 Mar 2004 15:58:18 +0000 |
| Subject: | note 40807 added to function.gethostbyaddr | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-66870@lists.php.net to get a copy of this message | ||
Note that sometime, people have broken DNS...
I mean that the IP resolve to a domain, but the reverse-resolution don't give the same IP.
I did a local test, putting a PTR record on my dns server to say 192.168.0.1 resolv to php.net .
When calling gethostbyaddr, I saw "Your host is php.net" ... So when you log the DNS
names, you have two options :
- Log the IP adresses to prevent fake ips
- Call gethostbyname on the result and verify that the IP is really the initial IP.
Note that not everyone can do that, only people with control on their own ip classes... Once, on the
real net, I got an IP resolving to "PROGRAM". It was obviously a fake record.
Note 2 for windows users : I noticed that some software takes the reverse record as athoritative. It
may allow people to do fake DNS entries if you do the reverse dns on your host. The best is to only
log IPs. Imagine someone with an host resolving to www.paypal.com. Next time you try to access
paypal, you will be redirected to his/her IP without even knowing it. Also faking update servers for
antivirus software, or winamp (there was a thread regarding this security problem because of a
problem in winamp updater if the remote server was faked) will be concerned.
----
Manual Page -- http://www.php.net/manual/en/function.gethostbyaddr.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+40807
Delete -- http://master.php.net/manage/user-notes.php?action=delete+40807&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+40807&report=yes
Search -- http://master.php.net/manage/user-notes.php