note 49540 added to function.phpinfo
| From: | cdmanatcoderdothu at osu1 dot php dot net | Date: | Tue, 01 Feb 2005 05:50:21 +0000 |
| Subject: | note 49540 added to function.phpinfo | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-84302@lists.php.net to get a copy of this message | ||
I've found this on the security part of the manual: if you append the string below to a php
file, it will produce the phpinfo() output regardless of the file contents. This can be prevented by
setting the "expose_php" to 0. However I think that this is a very little known
"feature", it's not mentioned anywhere on the site (you probably have to do some
digging in the source to know this) and IT SHOULD BE REMOVE ASAP, as it is an "easteregg",
an unecesarry feature and a SECURITY RISK!
?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000
----
Manual Page -- http://www.php.net/manual/en/function.phpinfo.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+49540
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+49540&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+49540&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+49540&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+49540&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+49540&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+49540&report=yes
Search -- http://master.php.net/manage/user-notes.php