Re: Thread Reading

From: Date: Thu, 19 Sep 2002 18:10:37 +0000
Subject: Re: Thread Reading
Groups: php.dev 
Request: Send a blank email to php-dev+get-88473@lists.php.net to get a copy of this message
Yep, and then you show off your super elite php build with phpinfo() and get to see ALL the environment variables of the user that apache was started as. How wonderful! Just require_once() your connection scripts if you're going to highlight_file or give a phps. Other methods are just plain stupid. I hope everyone on php-dev@ agrees that this isn't a "vulnerability" Met vriendelijke groeten, Devon H. O'Dell sitetronics.com Original Message: ----------------- From: Jedi/Sector One j@pureftpd.org Date: Thu, 19 Sep 2002 20:02:22 +0200 To: php-dev@lists.php.net Subject: Re: [PHP-DEV] Thread Reading On Thu, Sep 19, 2002 at 01:56:03PM -0400, devon@sitetronics.com wrote: > This is a security standard that is already inherent in the current phps > version. It is also not the job of PHP to save people from themselves. And sensitive cleartext data like SQL passwords can always be passed through environment variables. For instance, Apache has the 'Setenv' directive to set this, and the httpd.conf file can be made only readable by root. That way, publishing the source code doesn't reveal anything. -- __ /*- Frank DENIS (Jedi/Sector One) <j@42-Networks.Com> -*\ __ \ '/ <a href="http://www.PureFTPd.Org/"> Secure FTP Server </a> \' / \/ <a href="http://www.Jedi.Claranet.Fr/"> Misc. free software </a> \/ -------------------------------------------------------------------- mail2web - Check your email from the web at http://mail2web.com/ .

« previous php.dev (#88473) next »