Bug 10818 - HttpListener binds to all addresses
Summary: HttpListener binds to all addresses
Alias: None
Product: Class Libraries
Classification: Mono
Component: System ()
Version: 2.10.x
Hardware: Macintosh Mac OS
: --- normal
Target Milestone: Untriaged
Assignee: Bugzilla
Depends on:
Reported: 2013-03-01 11:56 UTC by Timo Dörr
Modified: 2014-05-24 01:55 UTC (History)
3 users (show)

Is this bug a regression?: ---
Last known good build:

minimal testcase to reproduce (329 bytes, application/octet-stream)
2013-03-01 11:56 UTC, Timo Dörr

Notice (2018-05-24): bugzilla.xamarin.com is now in read-only mode.

Please join us on Visual Studio Developer Community and in the Xamarin and Mono organizations on GitHub to continue tracking issues. Bugzilla will remain available for reference in read-only mode. We will continue to work on open Bugzilla bugs, copy them to the new locations as needed for follow-up, and add the new items under Related Links.

Our sincere thanks to everyone who has contributed on this bug tracker over the years. Thanks also for your understanding as we make these adjustments and improvements for the future.

Please create a new report on GitHub or Developer Community with your current version information, steps to reproduce, and relevant error messages or log files if you are hitting an issue that looks similar to this resolved bug and you do not yet see a matching new report.

Related Links:

Description Timo Dörr 2013-03-01 11:56:37 UTC
Created attachment 3521 [details]
minimal testcase to reproduce

The HttpListener class from System.Net does not respect the prefixes it is bound to, but instead listens on all interfaces. This makes it impossible for other programs, like apache to listen on the same port (but different ip), and may also be security-fatal (when listening only on localhost, it should really do so).

Attached is a small testcase that I ran with mono 2.10.9 on OS X Lion, listens on all devices and addresses. The same compiled program on Windows7 + MS .NET  only binds to localhost (requires to be run as administrator).
Comment 1 Miguel de Icaza [MSFT] 2014-02-12 12:07:39 UTC
Fixed in master
Comment 2 Kurt Ward 2014-05-23 13:17:51 UTC
This bug still exists in 3.4
Comment 3 Timo Dörr 2014-05-23 13:54:13 UTC
@Kurt Ward I can't confirm. Just tested the attached example and the bug seems fixed.

Tested with:

mono JIT compiler version 3.2.8 (Debian 3.2.8+dfsg-4ubuntu1)


Mono JIT compiler version 3.4.0 (tarball Thu Apr 24 10:23:10 UTC 2014)

both on Ubuntu 14.04.
Comment 4 Kurt Ward 2014-05-24 01:55:32 UTC
@Timo You are in fact correct!  The problem I was seeing was in a 3rd party lib that rewrites localhost to + by default.  I will inform them of the situation, as by default is not desirable.  Thanks!