Bug #17716 Updated: Webroot Disclosure in Error Output
ID: 17716
Updated by: mattmurphy@kc.rr.com
Reported By: mattmurphy@kc.rr.com
-Status: Bogus
+Status: Open
Bug Type: Output Control
Operating System: Win32
PHP Version: 4.2.1
New Comment:
Reading through php.ini, there are more security comments than lines of
configuration, so I would think this would be a default not to error
output to the user, at least. I would be more satisfied if the path of
the script were replaced with its name (such as switching
"C:\INETPUB\WWWROOT\SOMESCRIPT.PHP" with simply "SOMESCRIPT.PHP",
instead (at least in output error info; putting the path in logging
would probably be okay).
Previous Comments:
------------------------------------------------------------------------
[2002-06-11 18:25:25] edink@php.net
If you prefer security through obscurity you can put the following two
lines in your php.ini:
expose_php=Off
display_errors=Off
------------------------------------------------------------------------
[2002-06-11 18:08:27] mattmurphy@kc.rr.com
PHP 4.2.1 Path Disclosure Bug
System Details:
- Windows Me
- PHP 4.2.1 as CGI on Xitami 2.49d
- No modules
PHP 4.2.1 (possibly and probably others) can disclose path information
in error output. This is due to the fact that PHP discloses the full
path of failing scripts. For example, take the deliberately malformed
"Error.php":
<?php
@if ($action == "error") {
}
?>
This script produces the following output:
Parse error: parse error, unexpected T_IF in
C:\INETPUB\WWWROOT\error.php on line 2
As you can see, this includes the path of the web root in the error
data. This is surplus information at best, and at worst, data that
could aid an attack against the server.
While this script produces a parse error, it should be noted that
default installs of 4.2.1 produce this on such small events as notices
as well.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17716&edit=1
Thread (4 messages)