Bug #76970 [Com]: Password shown in Stacktrace
| From: | spam2 at rhsoft dot net | Date: | Thu, 04 Oct 2018 13:34:56 +0000 |
| Subject: | Bug #76970 [Com]: Password shown in Stacktrace | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217409@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76970&edit=1
ID: 76970
Comment by: spam2 at rhsoft dot net
Reported by: edv at aulenbacher dot de
Summary: Password shown in Stacktrace
Status: Open
Type: Bug
Package: PDO Core
Operating System: Linux
PHP Version: 7.2.10
Block user comment: N
Private report: N
New Comment:
since your adrdress ends with .de
https://www.golem.de/news/it-sicherheit-wie-ich-mein-passwort-im-stack-trace-fand-1704-127258.html
"warum es in PHP zu einfach ist, derartige Fehler zu produzieren" is simply nonsense
the following paragraph show the incompetence of the author in that context because you don't
need to enable display_errors to realize when things are going wrong - just set error_reporting to
E_ALL, disable dispaly_errors, configure error_log and write a crnjob mailing you anything which
appears there every 30 minites as we do in prudction for a decade now on some hundret webspaces
Display-Errors war bewusst aktiv
Es war kein Versehen, dass display_errors aktiviert war. Ich hatte mich vor längerer Zeit bewusst
dafür entschieden. Ursprünglich war die Option auf dem entsprechenden Server global
deaktiviert. Ich hatte allerdings bei einem Test einer neueren PHP-Version vor einiger Zeit gemerkt,
dass mehrere meiner PHP-Skripte Fehler enthielten, die durch das Abschalten der
display_errors-Option unbemerkt blieben. Um das zu verhindern, hielt ich es für sinnvoller, die
Anzeigen von Fehlermeldungen standardmäÃig zu aktivieren. Im Rückblick war das keine gute
Idee.
Previous Comments:
------------------------------------------------------------------------
[2018-10-04 13:29:52] spam2 at rhsoft dot net
irrelevant - php stacktraces are supposed to show the params and you must not echo out debug
informations to the client
------------------------------------------------------------------------
[2018-10-04 13:28:11] edv at aulenbacher dot de
addendum: The following constructor was used:
public PDO::__construct ( string $dsn, string $username, string $passwd)
------------------------------------------------------------------------
[2018-10-04 13:24:56] spam2 at rhsoft dot net
this is *not* a bug
you are not supposed to run production servers with display_errors nor should you echo out traces at
all
------------------------------------------------------------------------
[2018-10-04 13:22:16] edv at aulenbacher dot de
Description:
------------
When printing a stacktrace of a failed attempt to connect to a database, the password passed to
PDO-constructor is shown clearly.
Test script:
---------------
Connect via PDO to a database with a wrong password, catch that exception and do
file_put_contents('php://stderr', $e);
Expected result:
----------------
Password is not printed out readable.
Actual result:
--------------
Password is printed out readable.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76970&edit=1