[PEPr] Comment on HTTP::HTTP_FloodControl
| From: | Bertrand Mansion | Date: | Mon, 05 Mar 2007 09:52:29 +0000 |
| Subject: | [PEPr] Comment on HTTP::HTTP_FloodControl | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-45811@lists.php.net to get a copy of this message | ||
Bertrand Mansion (http://pear.php.net/user/mansion) has commented on the proposal for
HTTP::HTTP_FloodControl.
Comment:
I think you should make it a PHP5 package and use class constants instead
of defines and exceptions instead of pear errors. Or make your defines
more standard, using a longer prefix to avoid collisions.
I am also afraid $_SERVER['REMOTE_ADDR'] is not reliable, especially if
users are behind a router/proxy (they will share the same IP and they
might be quickly locked out on big traffic or big corporate sites where
users all connect at the same hour in the morning...).
As stated in this security report, it is also possible to spoof the IP
adress given by $_SERVER['HTTP_X_FORWARDED_FOR'], so beware :
http://osvdb.org/displayvuln.php?osvdb_id=23882
There is also this comment, but I doubt it is more useful:
http://fr2.php.net/manual/en/reserved.variables.php#70640
This one might need more investigation:
http://fr3.php.net/manual/en/function.getenv.php#41833
It would be interesting to know what the various books on PHP security
propose for such a problem.
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=476
--
Sent by PEPr, the automatic proposal system at http://pear.php.net