Bug #55497 [Com]: Credits URL Security ?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000

From: Date: Mon, 01 Feb 2016 15:58:21 +0000
Subject: Bug #55497 [Com]: Credits URL Security ?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198988@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=55497&edit=1

 ID:                 55497
 Comment by:         shadowsiam8 at gmail dot com
 Reported by:        mhaisley at gmail dot com
 Summary:            Credits URL Security
                     ?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000
 Status:             Not a bug
 Type:               Bug
 Package:            PHP options/info functions
 Operating System:   Any
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

That's really BS, what's the point of having those info available? If the server owner
what's to know about PHP stuff they can simply use the already know phpinfo(). What a waste of
resources having it to process such useless page. I may not be a bug, but it's a bad design
choice then. I got shocked when I found out about the param and realized that it was working in a
website of mine, where I don't have access to php.ini then I'm not sure if I can disable
such option. Fix... err... CHANGE it now! And I don't mean simply making it disabled by
default, I mean scratching it out for good.


Previous Comments:
------------------------------------------------------------------------
[2012-10-24 19:10:48] joaoprabelo at gmail dot com

nikic, but now I know when PHP is 5.5 or higher easily. Or isn't?

------------------------------------------------------------------------
[2012-10-10 17:33:17] nikic@php.net

@ian_dunn: The logo GUIDs have been removed in master. So presumably this issue (whether it actually
is one or not) will not exist anymore in PHP 5.5.

------------------------------------------------------------------------
[2012-10-10 17:26:03] ian_dunn at yahoo dot com

I agree with mhaisley, this is a security vulnerability and should be disabled by 
default. Many PCI compliance scanners will fail a site if it is turned on.

I realize that it's not a major vulnerability, but it does give attackers 
information that could help them compromise a system. What are the benefits of 
having it enabled by default? I can't think of any significant ones. Whatever 
benefits there are, they'd have to outweigh the downsides, and that doesn't seem 
likely in this case.

------------------------------------------------------------------------
[2012-09-12 06:42:41] support at ecommercewebsites dot com dot au

Nope - this is not a bug.
Just disable it in your config file.

------------------------------------------------------------------------
[2011-08-25 03:27:29] mhaisley at gmail dot com

Sorry, but it is a real issue. 

It should be disabled by default.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=55497


--
Edit this bug report at https://bugs.php.net/bug.php?id=55497&edit=1


Thread (8 messages)

« previous php.bugs (#198988) next »