Re: why the damn phpinfo() is so talkative?
| From: | Max Derkachev | Date: | Thu, 19 Oct 2000 10:27:16 +0000 |
| Subject: | Re: why the damn phpinfo() is so talkative? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-35506@lists.php.net to get a copy of this message | ||
Simon Roberts wrote:
> Which variables are you referring to? All of the content that I can see are
> run-time variables, information about the httpd process (and environment
> variables from it), some from root before it su's to nobody/apache..
On my servers where apache/php module is installed, phpinfo() gives me all the
environment variables of the user (namely, me), who compiled it in the section
"Environment" . While apache is running in it's own sandbox 'www', all my
environment for the moment I built php is showed. Even IRCNICK, IRCSERVER and
so on. If I pushed my ssh passphrase, I'm sure it wouild appear there too. As
the apache user is definitely not me, there are no any other ways for
phpinfo() to get those environment variables then fetch them from the php
module. I do not see any variables there that could be useful in debugging in
some way. None of them actually show the httpd daemon environment - just my
environment for the moment i built it.
And, even worse, all of them are exported to the $HTTP_ENV_VARS array. My own
PATH is merged with the Apache's user PATH and exported into
$HTTP_SERVER_VARS['PATH'].
As I now see, not only phpinfo() is a security breach, the php itself could
cause some troubles.
Configuration: PHP is 4.0.2, Apache 1.3.12, OS: FreeBSD 4.1 and Debian Linux
2.2
--
Best regards,
Max A. Derkachev mailto:kot@books.ru
Symbol-Plus Publishing Ltd.
phone: +7 (812) 265-0054, 265-1228, phone/fax: 567-8775
http://www.Books.Ru -- All Books of Russia