Re: why the damn phpinfo() is so talkative?

From: Date: Thu, 19 Oct 2000 10:49:19 +0000
Subject: Re: why the damn phpinfo() is so talkative?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-35507@lists.php.net to get a copy of this message
That's not the case. I did not mean the server where me myself is a designer, programmer and a sole user. What if I open an account with a php hosting provider and call phpinfo() in my own script? Or even make a script of the like: <?php $vars = array ($HTTP_SERVER_VARS, $HTTP_ENV_VARS); foreach ($vars as $var) { while (list ($k, $v) = each ($var) ) { print " $k ==> $v <br> "; } } ?> There would be no need in phpinfo() to reveal all the environment compiled in php. And safe mode which prevents me to read /etc/passwd won't help there much. Some things that could appear in user environment for a moment , could not be read anyhow from anything but the brain of the user who compiled php , if they aren't saved in php then. But they would appear in php predefined variables over and over if they do saved. Could you explain why they are there? What is the necessity of storing them in php executable? Rasmus Lerdorf wrote: > Don't make a page that has a phpinfo() call in it publically available. > It is as simple as that. There is nothing sensitive in there that can't > be obtained through a normal PHP script and the same rule would apply to > such a script. If you don't want to publish this information, do not > write a script that displays it. It's like asking why PHP allows one to > do: > > <? readfile("/etc/passwd") ?> -- Best regards, Max A. Derkachev mailto:kot@books.ru Symbol-Plus Publishing Ltd. phone: +7 (812) 265-0054, 265-1228, phone/fax: 567-8775 http://www.Books.Ru -- All Books of Russia

« previous php.dev (#35507) next »