Re: why the damn phpinfo() is so talkative?

From: Date: Thu, 19 Oct 2000 09:57:52 +0000
Subject: Re: why the damn phpinfo() is so talkative?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-35502@lists.php.net to get a copy of this message
Don't make a page that has a phpinfo() call in it publically available. It is as simple as that. There is nothing sensitive in there that can't be obtained through a normal PHP script and the same rule would apply to such a script. If you don't want to publish this information, do not write a script that displays it. It's like asking why PHP allows one to do: <? readfile("/etc/passwd") ?> (in non-safe-mode) -Rasmus (Doctor, it hurts when I do this! So don't do that!) On Thu, 19 Oct 2000, Max Derkachev wrote: > Could someone explain why phpinfo() is giving away all the info the C > compiler could get while building php? > Is there any need to show to the world my irc nick, or other personal > environment vars, which are inserted into php executable while building > ? Is there any need to store all that info in the php executable at all > ? What if someone pushed SSH or PGP passphrase, or something else quite > intimate into the environment before compiling php ? I guess such > behaviour of php is quite dangerous, especially if there are many > websites on one host - the value of information a cracker could get from > phpinfo() could not be overestimated. > Even if the usage of the phpinfo() or some parts of the information it > could give are restricted, nobody could ban a user to fetch php > executable in any form and run it without restrictions on his own site > to get the information. > > -- > Best regards, > Max A. Derkachev mailto:kot@books.ru > Symbol-Plus Publishing Ltd. > phone: +7 (812) 265-0054, 265-1228, phone/fax: 567-8775 > http://www.Books.Ru -- All Books of Russia > > > > >

« previous php.dev (#35502) next »