#23513 [Csd]: security flaw: info posted on newsgroup
| From: | rasmus@php.net | Date: | Tue, 06 May 2003 22:59:40 +0000 |
| Subject: | #23513 [Csd]: security flaw: info posted on newsgroup | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-39184@lists.php.net to get a copy of this message | ||
ID: 23513
Updated by: rasmus@php.net
Reported By: jlindsey at guarded dot net
Status: Closed
Bug Type: Feature/Change Request
Operating System: linux
PHP Version: 4.3.1
New Comment:
All our mailing lists are available via nntp and http on news.php.net.
The QA list this is sent to is a mailing list.
From a security perspective the level of publicity is irrelevant. If
you send out sensitive data to just a single external person you should
consider that data compromised.
Previous Comments:
------------------------------------------------------------------------
[2003-05-06 17:54:18] jlindsey at guarded dot net
Uhm, a disclaimer is not enough. No one reads them anyway. Why does
this info have to go to a totally public form? Can't it go to a
php-dev mailing list?
------------------------------------------------------------------------
[2003-05-06 15:23:15] rasmus@php.net
I have added a better disclaimer reminding people to use the
save feature and edit their report for sensitive data before sending it
in if they are worried about that.
------------------------------------------------------------------------
[2003-05-06 14:00:04] jlindsey at guarded dot net
After php compiles and runs its tests, there is an option to send the
information to the php developers. That option does not make it clear
that the information will be posted on a public newsgroup, php.qa
Yaaaaay! All the world can see detailed config info of one of my
company's internal machines, as well as other swell info (like my email
address).
Thanks php guys...that's great security!
Seriously...who thought this was a good idea? Stop! Stop it now!
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23513&edit=1