From: hadmut@... (Hadmut Danisch) Date: 2005-12-16T02:05:14+09:00 Subject: refurbishing ipaddr.rb - Class IPAddr? Hi, I was working a little bit with the IPAddr class defined in ipaddr.rb. From my point of view, it contains some shortcomings and flaws and should undergo some update or revision: - Security might be an issue. If I use the class in an environment with $SAFE=2 and a tainted IP address string, the underlying binary code issues an exception (correct), but ipaddr.rb does not deal with that correctly: Exception: invalid address (ArgumentError) /usr/lib/ruby/1.8/ipaddr.rb:423:in `initialize' It seems as if the networking libraries do not correctly deal with tainted variables or variables to be tainted. E.g. if I do a name resolution with Socket.gethostbyaddr, the result is not tainted, although it might contain any rubbish from the ugly world outside. - ipaddr.rb uses the same class for single IP addresses and IP address ranges. That's wrong. Although a single IP address might have an address mask length to describe the network it belongs to, it significantly differs from an IP address range. Furthermore, an address range requires different methods. I can't open a TCP connection to an address range, but I could have an each iterator for that range, and other stuff. It is also important to distinguish between an IP address and a DNS domain name. This is not the same. I strongly suggest to split this into three classes, address, address range, and DNS name. - Many new functions should be implemented. e.g. new IPv6 conversions like 6to4, IP address arithmetics, using IP addresses as hash keys, address classification, etc. This could include also functions about the operating system, e.g. ping, arp, and things like that. - DNS support is poor. There should be several new functions for DNS queries. Could be done as methods of a DNSname class. regards Hadmut