Re: why the damn phpinfo() is so talkative?
| From: | Max Derkachev | Date: | Thu, 19 Oct 2000 10:49:19 +0000 |
| Subject: | Re: why the damn phpinfo() is so talkative? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-35507@lists.php.net to get a copy of this message | ||
That's not the case. I did not mean the server where me myself is a designer,
programmer and a sole user. What if I open an account with a php hosting
provider and call phpinfo() in my own script? Or even make a script of the
like:
<?php
$vars = array ($HTTP_SERVER_VARS, $HTTP_ENV_VARS);
foreach ($vars as $var) {
while (list ($k, $v) = each ($var) ) {
print " $k ==> $v <br> ";
}
}
?>
There would be no need in phpinfo() to reveal all the environment compiled in
php. And safe mode which prevents me to read /etc/passwd won't help there
much.
Some things that could appear in user environment for a moment , could not be
read anyhow from anything but the brain of the user who compiled php , if
they aren't saved in php then. But they would appear in php predefined
variables over and over if they do saved.
Could you explain why they are there? What is the necessity of storing them
in php executable?
Rasmus Lerdorf wrote:
> Don't make a page that has a phpinfo() call in it publically available.
> It is as simple as that. There is nothing sensitive in there that can't
> be obtained through a normal PHP script and the same rule would apply to
> such a script. If you don't want to publish this information, do not
> write a script that displays it. It's like asking why PHP allows one to
> do:
>
> <? readfile("/etc/passwd") ?>
--
Best regards,
Max A. Derkachev mailto:kot@books.ru
Symbol-Plus Publishing Ltd.
phone: +7 (812) 265-0054, 265-1228, phone/fax: 567-8775
http://www.Books.Ru -- All Books of Russia