You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 263 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
phpBB 2.0.8a IP Spoofing Vulnerability
SecurityIn the vulnerability release here, Wang states that IPs can be spoofed and thereby hijacked when HTTP_FORWARDED_FOR is logging IP addresses. His suggestion is to take out the recording on this environment variable. Even though in theory this may be true, in practice it is a goose chase.

True anonymous remote proxy servers will not pass on HTTP_FORWARDED_FOR information, and will instead pass on REMOTE_ADDR. This means that the REMOTE_ADDR can then be spoofed. Per Wang's suggestion, the REMOTE_ADDR would need to be removed from being logged. So then, no IP gets logged into the sessions table?

Unless more detailed information can be provided, it is my personal opinion this is a wild goose chase. However, if you feel you need to implement his approach, please feel free. I only suggest that you read about TCP/IP and understand that remote proxy servers that act under true anonymity will still use REMOTE_ADDR and not HTTP_FORWARDED_FOR -- which then makes the fundamental REMOTE_ADDR supposedly spoofable.
Posted on Wednesday, April 21 @ 18:04:38 CEST by Zhen-Xjell
 
Related Links
· Computer Cops
· More about Security
· News by Zhen-Xjell


Most read story about Security:
PHP-Nuke admin.php security hole - PATCHED

Article Rating
Average Score: 3.66
Votes: 6


Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad


Options

 Printer Friendly Page  Printer Friendly Page

 Send to a Friend  Send to a Friend

Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.124 Seconds - 180 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::