Re: why the damn phpinfo() is so talkative?
| From: | Simon Roberts | Date: | Thu, 19 Oct 2000 09:51:54 +0000 |
| Subject: | Re: why the damn phpinfo() is so talkative? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-35500@lists.php.net to get a copy of this message | ||
> Could someone explain why phpinfo() is giving away all the info the C
> compiler could get while building php?
> Is there any need to show to the world my irc nick, or other personal
> environment vars, which are inserted into php executable while building
> ? Is there any need to store all that info in the php executable at all
> ? What if someone pushed SSH or PGP passphrase, or something else quite
> intimate into the environment before compiling php ? I guess such
> behaviour of php is quite dangerous, especially if there are many
> websites on one host - the value of information a cracker could get from
> phpinfo() could not be overestimated.
> Even if the usage of the phpinfo() or some parts of the information it
> could give are restricted, nobody could ban a user to fetch php
> executable in any form and run it without restrictions on his own site
> to get the information.
Which variables are you referring to? All of the content that I can see are
run-time variables, information about the httpd process (and environment
variables from it), some from root before it su's to nobody/apache..