Bug #17716 Updated: Webroot Disclosure in Error Output

From: Date: Tue, 11 Jun 2002 22:25:26 +0000
Subject: Bug #17716 Updated: Webroot Disclosure in Error Output
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-10173@lists.php.net to get a copy of this message
ID: 17716 Updated by: edink@php.net Reported By: mattmurphy@kc.rr.com -Status: Open +Status: Bogus Bug Type: Output Control Operating System: Win32 PHP Version: 4.2.1 New Comment: If you prefer security through obscurity you can put the following two lines in your php.ini: expose_php=Off display_errors=Off Previous Comments: ------------------------------------------------------------------------ [2002-06-11 18:08:27] mattmurphy@kc.rr.com PHP 4.2.1 Path Disclosure Bug System Details: - Windows Me - PHP 4.2.1 as CGI on Xitami 2.49d - No modules PHP 4.2.1 (possibly and probably others) can disclose path information in error output. This is due to the fact that PHP discloses the full path of failing scripts. For example, take the deliberately malformed "Error.php": <?php @if ($action == "error") { } ?> This script produces the following output: Parse error: parse error, unexpected T_IF in C:\INETPUB\WWWROOT\error.php on line 2 As you can see, this includes the path of the web root in the error data. This is surplus information at best, and at worst, data that could aid an attack against the server. While this script produces a parse error, it should be noted that default installs of 4.2.1 produce this on such small events as notices as well. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17716&edit=1

« previous php.bugs (#10173) next »