Req #67206 [Opn->Wfx]: Hide password in exception stack trace
| From: | aharvey@php.net | Date: | Mon, 05 May 2014 19:07:14 +0000 |
| Subject: | Req #67206 [Opn->Wfx]: Hide password in exception stack trace | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-185644@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67206&edit=1
ID: 67206
Updated by: aharvey@php.net
Reported by: sk at computer-leipzig dot com
Summary: Hide password in exception stack trace
-Status: Open
+Status: Wont fix
Type: Feature/Change Request
Package: PDO Core
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
I don't think this is worth the complexity, personally: you'd basically need a generic way
to mark arguments as "secure", update extensions to use them, and then update extensions
that reimplement stack dumping to honour that.
Seems like a lot of extra work for something that best practice has covered for years: don't
show your error messages to users.
Previous Comments:
------------------------------------------------------------------------
[2014-05-05 15:15:34] tyrael@php.net
you shouldn't enable display_errors in production so this shouldn't have any security
impact on your site (and secondly, an attacker shouldn't be able to use those credentials to
connect to your database from remotely, but that is not in the scope of this question), but hiding
the password by default would be a PITA for those people who are using the error reporting to track
down problems like a configuration error, where the connaction fails, because for some reason a
wrong password is used.
I'm not closing the issue, because I'm curious what other devs think, but imo it would be
a futile attempt to protect people this way.
------------------------------------------------------------------------
[2014-05-05 10:44:22] sk at computer-leipzig dot com
Description:
------------
Showing the password as default in the stack is for me a little bit against the philosophy to be a
practical web development language. I have no idea how hard it is mark the password with ****** (6
star signs) as default, and only when some configuration is changed show the real password.
I do not verify this, but I expect it is relevant for every database connection wich is using a
password. When it is mysql specific, a the change should apply to
PDO mysql only.
Expected result:
----------------
[15-Apr-2014 11:28:17] PHP Fatal error: Uncaught exception 'PDOException' with message
'SQLSTATE[HY000] [2002] Can't connect to local MySQL server through socket
'/var/run/mysqld/mysqld.sock' (2)' in
/opt/ZendFramework-1.10.8/library/Zend/Db/Adapter/Pdo/Abstract.php:129
Stack trace:
#0 /opt/ZendFramework-1.10.8/library/Zend/Db/Adapter/Pdo/Abstract.php(129):
PDO->__construct('mysql:host=loca...', 'a_database', '******',
Array)
#1 /opt/ZendFramework-1.10.8/library/Zend/Db/Adapter/Pdo/Mysql.php(96):
Zend_Db_Adapter_Pdo_Abstract->_connect()
Actual result:
--------------
[15-Apr-2014 11:28:17] PHP Fatal error: Uncaught exception 'PDOException' with message
'SQLSTATE[HY000] [2002] Can't connect to local MySQL server through socket
'/var/run/mysqld/mysqld.sock' (2)' in
/opt/ZendFramework-1.10.8/library/Zend/Db/Adapter/Pdo/Abstract.php:129
Stack trace:
#0 /opt/ZendFramework-1.10.8/library/Zend/Db/Adapter/Pdo/Abstract.php(129):
PDO->__construct('mysql:host=loca...', 'a_database',
'secure-password', Array)
#1 /opt/ZendFramework-1.10.8/library/Zend/Db/Adapter/Pdo/Mysql.php(96):
Zend_Db_Adapter_Pdo_Abstract->_connect()
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67206&edit=1