Re: why the damn phpinfo() is so talkative?

From: Date: Thu, 19 Oct 2000 09:51:54 +0000
Subject: Re: why the damn phpinfo() is so talkative?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-35500@lists.php.net to get a copy of this message
> Could someone explain why phpinfo() is giving away all the info the C > compiler could get while building php? > Is there any need to show to the world my irc nick, or other personal > environment vars, which are inserted into php executable while building > ? Is there any need to store all that info in the php executable at all > ? What if someone pushed SSH or PGP passphrase, or something else quite > intimate into the environment before compiling php ? I guess such > behaviour of php is quite dangerous, especially if there are many > websites on one host - the value of information a cracker could get from > phpinfo() could not be overestimated. > Even if the usage of the phpinfo() or some parts of the information it > could give are restricted, nobody could ban a user to fetch php > executable in any form and run it without restrictions on his own site > to get the information. Which variables are you referring to? All of the content that I can see are run-time variables, information about the httpd process (and environment variables from it), some from root before it su's to nobody/apache..

« previous php.dev (#35500) next »