Bug #17716 Updated: Webroot Disclosure in Error Output
| From: | edink@php.net | Date: | Tue, 11 Jun 2002 22:25:26 +0000 |
| Subject: | Bug #17716 Updated: Webroot Disclosure in Error Output | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-10173@lists.php.net to get a copy of this message | ||
ID: 17716
Updated by: edink@php.net
Reported By: mattmurphy@kc.rr.com
-Status: Open
+Status: Bogus
Bug Type: Output Control
Operating System: Win32
PHP Version: 4.2.1
New Comment:
If you prefer security through obscurity you can put the following two
lines in your php.ini:
expose_php=Off
display_errors=Off
Previous Comments:
------------------------------------------------------------------------
[2002-06-11 18:08:27] mattmurphy@kc.rr.com
PHP 4.2.1 Path Disclosure Bug
System Details:
- Windows Me
- PHP 4.2.1 as CGI on Xitami 2.49d
- No modules
PHP 4.2.1 (possibly and probably others) can disclose path information
in error output. This is due to the fact that PHP discloses the full
path of failing scripts. For example, take the deliberately malformed
"Error.php":
<?php
@if ($action == "error") {
}
?>
This script produces the following output:
Parse error: parse error, unexpected T_IF in
C:\INETPUB\WWWROOT\error.php on line 2
As you can see, this includes the path of the web root in the error
data. This is surplus information at best, and at worst, data that
could aid an attack against the server.
While this script produces a parse error, it should be noted that
default installs of 4.2.1 produce this on such small events as notices
as well.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17716&edit=1