|
Web Application Security
Fwd: PHP Easter Eggs Nov 28 2004 01:21PM Andi McLean (andi_mclean ntlworld com) (6 replies) Re: PHP Easter Eggs Nov 30 2004 04:12AM Serban Gh. Ghita (serban verasys ro) (2 replies) Re: Fwd: PHP Easter Eggs Nov 29 2004 04:17PM Saqib N Ali seagate com (3 replies) Re: Fwd: PHP Easter Eggs Nov 30 2004 08:53AM exon (exon home se) (2 replies) Re: PHP Easter Eggs Nov 30 2004 06:24PM Paul Fierro (pablo nothing com) (2 replies) Re: PHP Easter Eggs Dec 02 2004 04:35AM Jimi Thompson (jimi thompson gmail com) (4 replies) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) Re: PHP Easter Eggs Dec 02 2004 04:35AM Jimi Thompson (jimi thompson gmail com) (4 replies) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) Re: PHP Easter Eggs Nov 30 2004 06:24PM Paul Fierro (pablo nothing com) (2 replies) Re: PHP Easter Eggs Dec 02 2004 04:35AM Jimi Thompson (jimi thompson gmail com) (4 replies) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) Re: PHP Easter Eggs Dec 02 2004 04:35AM Jimi Thompson (jimi thompson gmail com) (4 replies) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) SQL injection (no single quotes used) Dec 09 2004 03:53PM Juan Carlos Calderon (johnccr yahoo com) (5 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM Mutallip Ablimit (mutax insi co jp) (2 replies) Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM Olivier G. Gaumond (olig monimap com) (1 replies) Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM Juan Carlos (johnccr yahoo com) (1 replies) RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM Brett Moore (brett moore security-assessment com) |
|
|
Privacy Statement |
>
>
>
> Hello Andi,
>
> I wouldn't classify this is a easter egg, especially since PHP provides a
> way to disable it, and also because it is not something the PHP group is
> trying to hide. Infact the setting to enable/disable this is very clearly
> stated in the php.ini, and is called "expose_php" .
>
> It is used for exposing what the webserver is running, just like server
> signature e.g. "Apache/1.3.26 (Unix) mod_gzip/1.3.26.1a PHP/4.3.3-dev " .
>
Still, if you turn off the apache server-signature but leave the
expose_php = On, you can get to know that PHP is actually running by
trying one or more of these Eggs. It's a Bad Thing (tm) if you ask me.
The code should be removed from PHP altogether since it doesn't exactly
provide much in the way of functionality. Possibly php_credits() could
be added as a function, the way php_info() is now. That way nobody could
glean information unawares, but the info would still be there if you
need it (and it would be much easier to come by).
> Thanks.
> Saqib Ali
> http://validate.sf.net
>
> Andi McLean <andi_mclean (at) ntlworld (dot) com [email concealed]> wrote on 11/28/2004 05:21:38 AM:
>
>
>>Hi,
>>
>>Does anyone know about the easter eggs in PHP?
>>I've just found out about them, My trust in PHP has just had a majorset
>
> back,
>
>>as I'm wondering what other easter eggs there are and can any be used to
>>circumenvent the protection I have on my site.
>>I feel like I now need to have a look at the source code, to find out
>
> what
>
>>else is there.
>>
>><anywebsite.that/uses.php>?=PHPE9568F36-D428-11d2-A769-00AA001ACF42
>>
>><anywebsite.thatuses.php>?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000
>>
>><anywebsite.thatuses.php>?=PHPE9568F34-D428-11d2-A769-00AA001ACF42
>>
>>eg
>>www.jsane.com/index.php?=PHPE9568F36-D428-11d2-A769-00AA001ACF42
>>www.jsane.com/index.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000
>>www.jsane.com/index.php?=PHPE9568F34-D428-11d2-A769-00AA001ACF42
>>
>>
>>Andi
>
>
>
>
[ reply ]