Re: why the damn phpinfo() is so talkative?
| From: | Zeev Suraski | Date: | Thu, 19 Oct 2000 13:26:46 +0000 |
| Subject: | Re: why the damn phpinfo() is so talkative? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-35528@lists.php.net to get a copy of this message | ||
At 13:34 19/10/2000, Max Derkachev wrote:
Thanks to all for your replies. Sorry, I've been mistaken. The variables don't compiled in php, as I see, they are exported from the shell. I made su to root and started apache (as I often do). Anyway, they are avauilable to the world, while they should not.They're not available to the world. They're available to the script author, and they're supposed to be available to the script author. Preventing the world from accessing them is your responsibility. You're not supposed to call phpinfo() on a world-viewable page, as is. However, I did consider phpinfo() to be a useful debugging tool to some extent, that could be made significantly more secure by removing the environment variables from it. You can do it by calling phpinfo(INFO_ALL & ~INFO_ENVIRONMENT). You can selectively ask phpinfo() to show only specific parts. However, again, note that it's not a security issue, any more than telling a user not to put readfile("/etc/passwd") in his script is. Zeev -- Zeev Suraski <zeev@zend.com> http://www.zend.com/