#23513 [NEW]: security flaw: info posted on newsgroup
| From: | jlindsey at guarded dot net | Date: | Tue, 06 May 2003 19:00:04 +0000 |
| Subject: | #23513 [NEW]: security flaw: info posted on newsgroup | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-39172@lists.php.net to get a copy of this message | ||
From: jlindsey at guarded dot net
Operating system: linux
PHP version: 4.3.1
PHP Bug Type: Feature/Change Request
Bug description: security flaw: info posted on newsgroup
After php compiles and runs its tests, there is an option to send the
information to the php developers. That option does not make it clear
that the information will be posted on a public newsgroup, php.qa
Yaaaaay! All the world can see detailed config info of one of my
company's internal machines, as well as other swell info (like my email
address).
Thanks php guys...that's great security!
Seriously...who thought this was a good idea? Stop! Stop it now!
--
Edit bug report at http://bugs.php.net/?id=23513&edit=1
--
Try a CVS snapshot: http://bugs.php.net/fix.php?id=23513&r=trysnapshot
Fixed in CVS: http://bugs.php.net/fix.php?id=23513&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=23513&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=23513&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=23513&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=23513&r=support
Expected behavior: http://bugs.php.net/fix.php?id=23513&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=23513&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=23513&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=23513&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=23513&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=23513&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=23513&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=23513&r=gnused