note 49540 added to function.phpinfo

From: Date: Tue, 01 Feb 2005 05:50:21 +0000
Subject: note 49540 added to function.phpinfo
Groups: php.notes 
Request: Send a blank email to php-notes+get-84302@lists.php.net to get a copy of this message
I've found this on the security part of the manual: if you append the string below to a php file, it will produce the phpinfo() output regardless of the file contents. This can be prevented by setting the "expose_php" to 0. However I think that this is a very little known "feature", it's not mentioned anywhere on the site (you probably have to do some digging in the source to know this) and IT SHOULD BE REMOVE ASAP, as it is an "easteregg", an unecesarry feature and a SECURITY RISK! ?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 ---- Manual Page -- http://www.php.net/manual/en/function.phpinfo.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+49540 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+49540&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+49540&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+49540&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+49540&report=yes&reason=useless Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+49540&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+49540&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#84302) next »