Re: why the damn phpinfo() is so talkative?

From: Date: Thu, 19 Oct 2000 20:34:20 +0000
Subject: Re: why the damn phpinfo() is so talkative?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-35557@lists.php.net to get a copy of this message
I agree with what your saying, though I do agree that hosted customers seeing certain environment variables can be undesireable. What do you think about a safe mode ini setting that could block certain "sensative" vars from being read? ----- Original Message ----- From: "Rasmus Lerdorf" <rasmus@linuxcare.com> To: "Max Derkachev" <kot@books.ru> Cc: <php-dev@lists.php.net> Sent: Thursday, October 19, 2000 9:39 AM Subject: Re: [PHP-DEV] why the damn phpinfo() is so talkative? > Well, you are simply wrong. PHP does not capture any compile-time > environment variables. These are run-time variables. If you don't want > your own env variables to be available to your web server, don't start > your web server with your own user id. The best approach is to create a > web user where you massage the environment to exactly what you want and > start your server from that user id. > > -Rasmus > > On Thu, 19 Oct 2000, Max Derkachev wrote: > > > > > Simon Roberts wrote: > > > > > Which variables are you referring to? All of the content that I can see are > > > run-time variables, information about the httpd process (and environment > > > variables from it), some from root before it su's to nobody/apache.. > > > > On my servers where apache/php module is installed, phpinfo() gives me all the > > environment variables of the user (namely, me), who compiled it in the section > > "Environment" . While apache is running in it's own sandbox > > 'www', all my > > environment for the moment I built php is showed. Even IRCNICK, IRCSERVER and > > so on. If I pushed my ssh passphrase, I'm sure it wouild appear there too. As > > the apache user is definitely not me, there are no any other ways for > > phpinfo() to get those environment variables then fetch them from the php > > module. I do not see any variables there that could be useful in debugging in > > some way. None of them actually show the httpd daemon environment - just my > > environment for the moment i built it. > > And, even worse, all of them are exported to the $HTTP_ENV_VARS array. My own > > PATH is merged with the Apache's user PATH and exported into > > $HTTP_SERVER_VARS['PATH']. > > As I now see, not only phpinfo() is a security breach, the php itself could > > cause some troubles. > > Configuration: PHP is 4.0.2, Apache 1.3.12, OS: FreeBSD 4.1 and Debian Linux > > 2.2 > > > > -- > > Best regards, > > Max A. Derkachev mailto:kot@books.ru > > Symbol-Plus Publishing Ltd. > > phone: +7 (812) 265-0054, 265-1228, phone/fax: 567-8775 > > http://www.Books.Ru -- All Books of Russia > > > > > > > > > > > > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.dev (#35557) next »