Re: why the damn phpinfo() is so talkative?

From: Date: Thu, 19 Oct 2000 13:26:46 +0000
Subject: Re: why the damn phpinfo() is so talkative?
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-35528@lists.php.net to get a copy of this message
At 13:34 19/10/2000, Max Derkachev wrote:
Thanks to all for your replies. Sorry, I've been mistaken. The variables don't compiled in php, as I see, they are exported from the shell. I made su to root and started apache (as I often do). Anyway, they are avauilable to the world, while they should not.
They're not available to the world. They're available to the script author, and they're supposed to be available to the script author. Preventing the world from accessing them is your responsibility. You're not supposed to call phpinfo() on a world-viewable page, as is. However, I did consider phpinfo() to be a useful debugging tool to some extent, that could be made significantly more secure by removing the environment variables from it. You can do it by calling phpinfo(INFO_ALL & ~INFO_ENVIRONMENT). You can selectively ask phpinfo() to show only specific parts. However, again, note that it's not a security issue, any more than telling a user not to put readfile("/etc/passwd") in his script is. Zeev -- Zeev Suraski <zeev@zend.com> http://www.zend.com/

« previous php.dev (#35528) next »