Re: why the damn phpinfo() is so talkative?
| From: | Jason Greene | Date: | Thu, 19 Oct 2000 20:34:20 +0000 |
| Subject: | Re: why the damn phpinfo() is so talkative? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-35557@lists.php.net to get a copy of this message | ||
I agree with what your saying, though I do agree that hosted customers seeing certain environment
variables can be undesireable.
What do you think about a safe mode ini setting that could block certain "sensative" vars
from being read?
----- Original Message -----
From: "Rasmus Lerdorf" <rasmus@linuxcare.com>
To: "Max Derkachev" <kot@books.ru>
Cc: <php-dev@lists.php.net>
Sent: Thursday, October 19, 2000 9:39 AM
Subject: Re: [PHP-DEV] why the damn phpinfo() is so talkative?
> Well, you are simply wrong. PHP does not capture any compile-time
> environment variables. These are run-time variables. If you don't want
> your own env variables to be available to your web server, don't start
> your web server with your own user id. The best approach is to create a
> web user where you massage the environment to exactly what you want and
> start your server from that user id.
>
> -Rasmus
>
> On Thu, 19 Oct 2000, Max Derkachev wrote:
>
> >
> > Simon Roberts wrote:
> >
> > > Which variables are you referring to? All of the content that I can see are
> > > run-time variables, information about the httpd process (and environment
> > > variables from it), some from root before it su's to nobody/apache..
> >
> > On my servers where apache/php module is installed, phpinfo() gives me all the
> > environment variables of the user (namely, me), who compiled it in the section
> > "Environment" . While apache is running in it's own sandbox
> > 'www', all my
> > environment for the moment I built php is showed. Even IRCNICK, IRCSERVER and
> > so on. If I pushed my ssh passphrase, I'm sure it wouild appear there too. As
> > the apache user is definitely not me, there are no any other ways for
> > phpinfo() to get those environment variables then fetch them from the php
> > module. I do not see any variables there that could be useful in debugging in
> > some way. None of them actually show the httpd daemon environment - just my
> > environment for the moment i built it.
> > And, even worse, all of them are exported to the $HTTP_ENV_VARS array. My own
> > PATH is merged with the Apache's user PATH and exported into
> > $HTTP_SERVER_VARS['PATH'].
> > As I now see, not only phpinfo() is a security breach, the php itself could
> > cause some troubles.
> > Configuration: PHP is 4.0.2, Apache 1.3.12, OS: FreeBSD 4.1 and Debian Linux
> > 2.2
> >
> > --
> > Best regards,
> > Max A. Derkachev mailto:kot@books.ru
> > Symbol-Plus Publishing Ltd.
> > phone: +7 (812) 265-0054, 265-1228, phone/fax: 567-8775
> > http://www.Books.Ru -- All Books of Russia
> >
> >
> >
> >
> >
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>