Re: why the damn phpinfo() is so talkative?
| From: | Rasmus Lerdorf | Date: | Thu, 19 Oct 2000 09:57:52 +0000 |
| Subject: | Re: why the damn phpinfo() is so talkative? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-35502@lists.php.net to get a copy of this message | ||
Don't make a page that has a phpinfo() call in it publically available.
It is as simple as that. There is nothing sensitive in there that can't
be obtained through a normal PHP script and the same rule would apply to
such a script. If you don't want to publish this information, do not
write a script that displays it. It's like asking why PHP allows one to
do:
<? readfile("/etc/passwd") ?>
(in non-safe-mode)
-Rasmus
(Doctor, it hurts when I do this! So don't do that!)
On Thu, 19 Oct 2000, Max Derkachev wrote:
> Could someone explain why phpinfo() is giving away all the info the C
> compiler could get while building php?
> Is there any need to show to the world my irc nick, or other personal
> environment vars, which are inserted into php executable while building
> ? Is there any need to store all that info in the php executable at all
> ? What if someone pushed SSH or PGP passphrase, or something else quite
> intimate into the environment before compiling php ? I guess such
> behaviour of php is quite dangerous, especially if there are many
> websites on one host - the value of information a cracker could get from
> phpinfo() could not be overestimated.
> Even if the usage of the phpinfo() or some parts of the information it
> could give are restricted, nobody could ban a user to fetch php
> executable in any form and run it without restrictions on his own site
> to get the information.
>
> --
> Best regards,
> Max A. Derkachev mailto:kot@books.ru
> Symbol-Plus Publishing Ltd.
> phone: +7 (812) 265-0054, 265-1228, phone/fax: 567-8775
> http://www.Books.Ru -- All Books of Russia
>
>
>
>
>