Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 13 Nov 2003 13:40:45 +0100
From:      Stijn Hoop <stijn@win.tue.nl>
To:        FreeBSD Security List <security@freebsd.org>
Subject:   Re: Apache leaks sensitive info in PHP phpinfo() calls
Message-ID:  <20031113124045.GG8993@pcwin002.win.tue.nl>
In-Reply-To: <20031113102619.GB58969@users.munk.nu>
References:  <20031113102619.GB58969@users.munk.nu>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
On Thu, Nov 13, 2003 at 10:26:19AM +0000, Jez Hancock wrote:
> I wanted to get some opinions on this subject before I submit a PR about
> it.  I don't know if there are any pitfalls with the 'fix' I suggested
> and though it best to run it past people here before submitting.  If
> there's a better place to post this please let me know (freebsd-ports?).

FWIW, I have been doing a variation on this for a long time, no ill effects.
I also think it is unwise to propagate every environment variable, but the
solution should be implemented by the Apache people I think.

Just a quick 'me too',

--Stijn

-- 
This sentence contradicts itself -- no actually it doesn't.
		-- Hofstadter

[-- Attachment #2 --]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (FreeBSD)

iD8DBQE/s3vNY3r/tLQmfWcRApi+AJ9EWGzzZ9L/qWqO4d9zhfSpcogUQgCdGHZr
GUxiJgrLRYc8vTKEQp1E75s=
=kbI6
-----END PGP SIGNATURE-----
help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20031113124045.GG8993>