note 49540 rejected from function.phpinfo by didou
| From: | didou@php.net | Date: | Fri, 04 Feb 2005 10:33:11 +0000 |
| Subject: | note 49540 rejected from function.phpinfo by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-84506@lists.php.net to get a copy of this message | ||
Note Submitter: cd man at coder dot hu
----
I've found this on the security part of the manual: if you append the string below to a php
file, it will produce the phpinfo() output regardless of the file contents. This can be prevented by
setting the "expose_php" to 0. However I think that this is a very little known
"feature", it's not mentioned anywhere on the site (you probably have to do some
digging in the source to know this) and IT SHOULD BE REMOVE ASAP, as it is an "easteregg",
an unecesarry feature and a SECURITY RISK!
?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000