note 40807 added to function.gethostbyaddr

From: Date: Mon, 15 Mar 2004 15:58:18 +0000
Subject: note 40807 added to function.gethostbyaddr
Groups: php.notes 
Request: Send a blank email to php-notes+get-66870@lists.php.net to get a copy of this message
Note that sometime, people have broken DNS... I mean that the IP resolve to a domain, but the reverse-resolution don't give the same IP. I did a local test, putting a PTR record on my dns server to say 192.168.0.1 resolv to php.net . When calling gethostbyaddr, I saw "Your host is php.net" ... So when you log the DNS names, you have two options : - Log the IP adresses to prevent fake ips - Call gethostbyname on the result and verify that the IP is really the initial IP. Note that not everyone can do that, only people with control on their own ip classes... Once, on the real net, I got an IP resolving to "PROGRAM". It was obviously a fake record. Note 2 for windows users : I noticed that some software takes the reverse record as athoritative. It may allow people to do fake DNS entries if you do the reverse dns on your host. The best is to only log IPs. Imagine someone with an host resolving to www.paypal.com. Next time you try to access paypal, you will be redirected to his/her IP without even knowing it. Also faking update servers for antivirus software, or winamp (there was a thread regarding this security problem because of a problem in winamp updater if the remote server was faked) will be concerned. ---- Manual Page -- http://www.php.net/manual/en/function.gethostbyaddr.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+40807 Delete -- http://master.php.net/manage/user-notes.php?action=delete+40807&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+40807&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#66870) next »