Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Fwd: PHP Easter Eggs Nov 28 2004 01:21PM
Andi McLean (andi_mclean ntlworld com) (6 replies)
Re: PHP Easter Eggs Nov 30 2004 04:19AM
Serban Gh. Ghita (serban verasys ro)
Re: PHP Easter Eggs Nov 30 2004 04:12AM
Serban Gh. Ghita (serban verasys ro) (2 replies)
Re: PHP Easter Eggs Nov 30 2004 02:40AM
Harrison Gladden (hgladden gmail com) (4 replies)
Re: PHP Easter Eggs Dec 06 2004 09:45PM
Antonio Varni (antonio varni gmail com)
Re: PHP Easter Eggs Dec 06 2004 09:45PM
Antonio Varni (antonio varni gmail com)
RE: PHP Easter Eggs Nov 30 2004 07:39PM
V. Poddubnyy (vpoddubniy mail ru)
RE: PHP Easter Eggs Nov 30 2004 07:39PM
V. Poddubnyy (vpoddubniy mail ru)
Re: PHP Easter Eggs Nov 30 2004 02:40AM
Harrison Gladden (hgladden gmail com) (4 replies)
Re: PHP Easter Eggs Dec 06 2004 09:45PM
Antonio Varni (antonio varni gmail com)
Re: PHP Easter Eggs Dec 06 2004 09:45PM
Antonio Varni (antonio varni gmail com)
RE: PHP Easter Eggs Nov 30 2004 07:39PM
V. Poddubnyy (vpoddubniy mail ru)
RE: PHP Easter Eggs Nov 30 2004 07:39PM
V. Poddubnyy (vpoddubniy mail ru)
Re: Fwd: PHP Easter Eggs Nov 29 2004 08:54PM
Alexander Klimov (alserkli inbox ru)
Re: Fwd: PHP Easter Eggs Nov 29 2004 04:17PM
Saqib N Ali seagate com (2 replies)
Re: Fwd: PHP Easter Eggs Nov 30 2004 08:53AM
exon (exon home se) (2 replies)
Re: PHP Easter Eggs Nov 30 2004 06:24PM
Paul Fierro (pablo nothing com) (2 replies)
Re: PHP Easter Eggs Dec 02 2004 04:35AM
Jimi Thompson (jimi thompson gmail com) (5 replies)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
I don't think we can speculate what other holes are in there, or how much
faith we lost in the team. The fact is that these jovial additions reveal
PHP version. This is no more damaging than when server sig is left on and
also by the looks of it, no more difficult to fix.

----- Original Message -----
From: "Jimi Thompson" <jimi.thompson (at) gmail (dot) com [email concealed]>
To: "Paul Fierro" <pablo (at) nothing (dot) com [email concealed]>
Cc: <webappsec (at) securityfocus (dot) com [email concealed]>
Sent: Thursday, December 02, 2004 4:35 AM
Subject: Re: PHP Easter Eggs

> I think the real concern here is that they've put these "hidden little
> gems" in there in the first place. Since no one else seems to want to
> come right out and say it, I'll do it. If that's in there, what else
> is in there that we just haven't found yet?
>
> A photograph of someone's dog in and of itself isn't very threatening.
> However, when you expect your system and and application to be fairly
> secure and you find something like this, you have to wonder what else
> is there that's also not "public".
>
> Does this mean that if I go join up on the PHP developers mailing
> lists/forums that I can find out about other stuff that might enable
> me to compromise a widely used e-commerce application like osCommerce?
> or nukeCommerce? or phpShop? or X-cart? or any of the other scads of
> both commercial and opensource e-commerce suites that are available.
>
> The only comment I have for the PHP development team is that this is
> _VERY_ uncool.
>
> 2 cents,
>
> Jimi
>
>
> On Tue, 30 Nov 2004 12:24:22 -0600, Paul Fierro <pablo (at) nothing (dot) com [email concealed]> wrote:
> > On 11/30/2004 2:53 AM, exon <exon (at) home (dot) se [email concealed]> wrote:
> >
> > > The code should be removed from PHP altogether since it doesn't
exactly
> > > provide much in the way of functionality. Possibly php_credits() could
> > > be added as a function, the way php_info() is now. That way nobody
could
> > > glean information unawares, but the info would still be there if you
> > > need it (and it would be much easier to come by).
> >
> > A function named phpcredits() already exists:
> >
> > http://www.php.net/phpcredits
> >
> > Paul
> >
> >
>
>
> --
> Thanks,
>
> Jimi

[ reply ]
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
I don't think we can speculate what other holes are in there, or how much<br/>
faith we lost in the team. The fact is that these jovial additions reveal<br/>
PHP version. This is no more damaging than when server sig is left on and<br/>
also by the looks of it, no more difficult to fix.<br/>
<br/>
----- Original Message ----- <br/>
From: "Jimi Thompson" <jimi.thompson (at) gmail (dot) com [email concealed]><br/>
To: "Paul Fierro" <pablo (at) nothing (dot) com [email concealed]><br/>
Cc: <webappsec (at) securityfocus (dot) com [email concealed]><br/>
Sent: Thursday, December 02, 2004 4:35 AM<br/>
Subject: Re: PHP Easter Eggs<br/>
<br/>
> I think the real concern here is that they've put these "hidden little<br/>
> gems" in there in the first place. Since no one else seems to want to<br/>
> come right out and say it, I'll do it. If that's in there, what else<br/>
> is in there that we just haven't found yet?<br/>
><br/>
> A photograph of someone's dog in and of itself isn't very threatening.<br/>
> However, when you expect your system and and application to be fairly<br/>
> secure and you find something like this, you have to wonder what else<br/>
> is there that's also not "public".<br/>
><br/>
> Does this mean that if I go join up on the PHP developers mailing<br/>
> lists/forums that I can find out about other stuff that might enable<br/>
> me to compromise a widely used e-commerce application like osCommerce?<br/>
> or nukeCommerce? or phpShop? or X-cart? or any of the other scads of<br/>
> both commercial and opensource e-commerce suites that are available.<br/>
><br/>
> The only comment I have for the PHP development team is that this is<br/>
> _VERY_ uncool.<br/>
><br/>
> 2 cents,<br/>
><br/>
> Jimi<br/>
><br/>
><br/>
> On Tue, 30 Nov 2004 12:24:22 -0600, Paul Fierro <pablo (at) nothing (dot) com [email concealed]> wrote:<br/>
> > On 11/30/2004 2:53 AM, exon <exon (at) home (dot) se [email concealed]> wrote:<br/>
> ><br/>
> > > The code should be removed from PHP altogether since it doesn't<br/>
exactly<br/>
> > > provide much in the way of functionality. Possibly php_credits() could<br/>
> > > be added as a function, the way php_info() is now. That way nobody<br/>
could<br/>
> > > glean information unawares, but the info would still be there if you<br/>
> > > need it (and it would be much easier to come by).<br/>
> ><br/>
> > A function named phpcredits() already exists:<br/>
> ><br/>
> > http://www.php.net/phpcredits<br/>
> ><br/>
> > Paul<br/>
> ><br/>
> ><br/>
><br/>
><br/>
> -- <br/>
> Thanks,<br/>
><br/>
> Jimi

[ reply ]
Re: PHP Easter Eggs Dec 02 2004 04:35AM
Jimi Thompson (jimi thompson gmail com) (3 replies)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
Re: PHP Easter Eggs Nov 30 2004 06:24PM
Paul Fierro (pablo nothing com) (2 replies)
Re: PHP Easter Eggs Dec 02 2004 04:35AM
Jimi Thompson (jimi thompson gmail com) (5 replies)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
I don't think we can speculate what other holes are in there, or how much<br/><br/>
faith we lost in the team. The fact is that these jovial additions reveal<br/><br/>
PHP version. This is no more damaging than when server sig is left on and<br/><br/>
also by the looks of it, no more difficult to fix.<br/><br/>
<br/><br/>
----- Original Message ----- <br/><br/>
From: "Jimi Thompson" <jimi.thompson (at) gmail (dot) com [email concealed]><br/><br/>
To: "Paul Fierro" <pablo (at) nothing (dot) com [email concealed]><br/><br/>
Cc: <webappsec (at) securityfocus (dot) com [email concealed]><br/><br/>
Sent: Thursday, December 02, 2004 4:35 AM<br/><br/>
Subject: Re: PHP Easter Eggs<br/><br/>
<br/><br/>
> I think the real concern here is that they've put these "hidden little<br/><br/>
> gems" in there in the first place. Since no one else seems to want to<br/><br/>
> come right out and say it, I'll do it. If that's in there, what else<br/><br/>
> is in there that we just haven't found yet?<br/><br/>
><br/><br/>
> A photograph of someone's dog in and of itself isn't very threatening.<br/><br/>
> However, when you expect your system and and application to be fairly<br/><br/>
> secure and you find something like this, you have to wonder what else<br/><br/>
> is there that's also not "public".<br/><br/>
><br/><br/>
> Does this mean that if I go join up on the PHP developers mailing<br/><br/>
> lists/forums that I can find out about other stuff that might enable<br/><br/>
> me to compromise a widely used e-commerce application like osCommerce?<br/><br/>
> or nukeCommerce? or phpShop? or X-cart? or any of the other scads of<br/><br/>
> both commercial and opensource e-commerce suites that are available.<br/><br/>
><br/><br/>
> The only comment I have for the PHP development team is that this is<br/><br/>
> _VERY_ uncool.<br/><br/>
><br/><br/>
> 2 cents,<br/><br/>
><br/><br/>
> Jimi<br/><br/>
><br/><br/>
><br/><br/>
> On Tue, 30 Nov 2004 12:24:22 -0600, Paul Fierro <pablo (at) nothing (dot) com [email concealed]> wrote:<br/><br/>
> > On 11/30/2004 2:53 AM, exon <exon (at) home (dot) se [email concealed]> wrote:<br/><br/>
> ><br/><br/>
> > > The code should be removed from PHP altogether since it doesn't<br/><br/>
exactly<br/><br/>
> > > provide much in the way of functionality. Possibly php_credits() could<br/><br/>
> > > be added as a function, the way php_info() is now. That way nobody<br/><br/>
could<br/><br/>
> > > glean information unawares, but the info would still be there if you<br/><br/>
> > > need it (and it would be much easier to come by).<br/><br/>
> ><br/><br/>
> > A function named phpcredits() already exists:<br/><br/>
> ><br/><br/>
> > http://www.php.net/phpcredits<br/><br/>
> ><br/><br/>
> > Paul<br/><br/>
> ><br/><br/>
> ><br/><br/>
><br/><br/>
><br/><br/>
> -- <br/><br/>
> Thanks,<br/><br/>
><br/><br/>
> Jimi

[ reply ]
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
I don't think we can speculate what other holes are in there, or how much<br/><br/><br/>
faith we lost in the team. The fact is that these jovial additions reveal<br/><br/><br/>
PHP version. This is no more damaging than when server sig is left on and<br/><br/><br/>
also by the looks of it, no more difficult to fix.<br/><br/><br/>
<br/><br/><br/>
----- Original Message ----- <br/><br/><br/>
From: "Jimi Thompson" <jimi.thompson (at) gmail (dot) com [email concealed]><br/><br/><br/>
To: "Paul Fierro" <pablo (at) nothing (dot) com [email concealed]><br/><br/><br/>
Cc: <webappsec (at) securityfocus (dot) com [email concealed]><br/><br/><br/>
Sent: Thursday, December 02, 2004 4:35 AM<br/><br/><br/>
Subject: Re: PHP Easter Eggs<br/><br/><br/>
<br/><br/><br/>
> I think the real concern here is that they've put these "hidden little<br/><br/><br/>
> gems" in there in the first place. Since no one else seems to want to<br/><br/><br/>
> come right out and say it, I'll do it. If that's in there, what else<br/><br/><br/>
> is in there that we just haven't found yet?<br/><br/><br/>
><br/><br/><br/>
> A photograph of someone's dog in and of itself isn't very threatening.<br/><br/><br/>
> However, when you expect your system and and application to be fairly<br/><br/><br/>
> secure and you find something like this, you have to wonder what else<br/><br/><br/>
> is there that's also not "public".<br/><br/><br/>
><br/><br/><br/>
> Does this mean that if I go join up on the PHP developers mailing<br/><br/><br/>
> lists/forums that I can find out about other stuff that might enable<br/><br/><br/>
> me to compromise a widely used e-commerce application like osCommerce?<br/><br/><br/>
> or nukeCommerce? or phpShop? or X-cart? or any of the other scads of<br/><br/><br/>
> both commercial and opensource e-commerce suites that are available.<br/><br/><br/>
><br/><br/><br/>
> The only comment I have for the PHP development team is that this is<br/><br/><br/>
> _VERY_ uncool.<br/><br/><br/>
><br/><br/><br/>
> 2 cents,<br/><br/><br/>
><br/><br/><br/>
> Jimi<br/><br/><br/>
><br/><br/><br/>
><br/><br/><br/>
> On Tue, 30 Nov 2004 12:24:22 -0600, Paul Fierro <pablo (at) nothing (dot) com [email concealed]> wrote:<br/><br/><br/>
> > On 11/30/2004 2:53 AM, exon <exon (at) home (dot) se [email concealed]> wrote:<br/><br/><br/>
> ><br/><br/><br/>
> > > The code should be removed from PHP altogether since it doesn't<br/><br/><br/>
exactly<br/><br/><br/>
> > > provide much in the way of functionality. Possibly php_credits() could<br/><br/><br/>
> > > be added as a function, the way php_info() is now. That way nobody<br/><br/><br/>
could<br/><br/><br/>
> > > glean information unawares, but the info would still be there if you<br/><br/><br/>
> > > need it (and it would be much easier to come by).<br/><br/><br/>
> ><br/><br/><br/>
> > A function named phpcredits() already exists:<br/><br/><br/>
> ><br/><br/><br/>
> > http://www.php.net/phpcredits<br/><br/><br/>
> ><br/><br/><br/>
> > Paul<br/><br/><br/>
> ><br/><br/><br/>
> ><br/><br/><br/>
><br/><br/><br/>
><br/><br/><br/>
> -- <br/><br/><br/>
> Thanks,<br/><br/><br/>
><br/><br/><br/>
> Jimi

[ reply ]
Re: PHP Easter Eggs Dec 02 2004 04:35AM
Jimi Thompson (jimi thompson gmail com) (3 replies)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
Re: Fwd: PHP Easter Eggs Nov 30 2004 08:53AM
exon (exon home se) (2 replies)
Re: PHP Easter Eggs Nov 30 2004 06:24PM
Paul Fierro (pablo nothing com) (2 replies)
Re: PHP Easter Eggs Dec 02 2004 04:35AM
Jimi Thompson (jimi thompson gmail com) (5 replies)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
I don't think we can speculate what other holes are in there, or how much<br/><br/><br/><br/>
faith we lost in the team. The fact is that these jovial additions reveal<br/><br/><br/><br/>
PHP version. This is no more damaging than when server sig is left on and<br/><br/><br/><br/>
also by the looks of it, no more difficult to fix.<br/><br/><br/><br/>
<br/><br/><br/><br/>
----- Original Message ----- <br/><br/><br/><br/>
From: "Jimi Thompson" <jimi.thompson (at) gmail (dot) com [email concealed]><br/><br/><br/><br/>
To: "Paul Fierro" <pablo (at) nothing (dot) com [email concealed]><br/><br/><br/><br/>
Cc: <webappsec (at) securityfocus (dot) com [email concealed]><br/><br/><br/><br/>
Sent: Thursday, December 02, 2004 4:35 AM<br/><br/><br/><br/>
Subject: Re: PHP Easter Eggs<br/><br/><br/><br/>
<br/><br/><br/><br/>
> I think the real concern here is that they've put these "hidden little<br/><br/><br/><br/>
> gems" in there in the first place. Since no one else seems to want to<br/><br/><br/><br/>
> come right out and say it, I'll do it. If that's in there, what else<br/><br/><br/><br/>
> is in there that we just haven't found yet?<br/><br/><br/><br/>
><br/><br/><br/><br/>
> A photograph of someone's dog in and of itself isn't very threatening.<br/><br/><br/><br/>
> However, when you expect your system and and application to be fairly<br/><br/><br/><br/>
> secure and you find something like this, you have to wonder what else<br/><br/><br/><br/>
> is there that's also not "public".<br/><br/><br/><br/>
><br/><br/><br/><br/>
> Does this mean that if I go join up on the PHP developers mailing<br/><br/><br/><br/>
> lists/forums that I can find out about other stuff that might enable<br/><br/><br/><br/>
> me to compromise a widely used e-commerce application like osCommerce?<br/><br/><br/><br/>
> or nukeCommerce? or phpShop? or X-cart? or any of the other scads of<br/><br/><br/><br/>
> both commercial and opensource e-commerce suites that are available.<br/><br/><br/><br/>
><br/><br/><br/><br/>
> The only comment I have for the PHP development team is that this is<br/><br/><br/><br/>
> _VERY_ uncool.<br/><br/><br/><br/>
><br/><br/><br/><br/>
> 2 cents,<br/><br/><br/><br/>
><br/><br/><br/><br/>
> Jimi<br/><br/><br/><br/>
><br/><br/><br/><br/>
><br/><br/><br/><br/>
> On Tue, 30 Nov 2004 12:24:22 -0600, Paul Fierro <pablo (at) nothing (dot) com [email concealed]> wrote:<br/><br/><br/><br/>
> > On 11/30/2004 2:53 AM, exon <exon (at) home (dot) se [email concealed]> wrote:<br/><br/><br/><br/>
> ><br/><br/><br/><br/>
> > > The code should be removed from PHP altogether since it doesn't<br/><br/><br/><br/>
exactly<br/><br/><br/><br/>
> > > provide much in the way of functionality. Possibly php_credits() could<br/><br/><br/><br/>
> > > be added as a function, the way php_info() is now. That way nobody<br/><br/><br/><br/>
could<br/><br/><br/><br/>
> > > glean information unawares, but the info would still be there if you<br/><br/><br/><br/>
> > > need it (and it would be much easier to come by).<br/><br/><br/><br/>
> ><br/><br/><br/><br/>
> > A function named phpcredits() already exists:<br/><br/><br/><br/>
> ><br/><br/><br/><br/>
> > http://www.php.net/phpcredits<br/><br/><br/><br/>
> ><br/><br/><br/><br/>
> > Paul<br/><br/><br/><br/>
> ><br/><br/><br/><br/>
> ><br/><br/><br/><br/>
><br/><br/><br/><br/>
><br/><br/><br/><br/>
> -- <br/><br/><br/><br/>
> Thanks,<br/><br/><br/><br/>
><br/><br/><br/><br/>
> Jimi

[ reply ]
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
I don't think we can speculate what other holes are in there, or how much<br/><br/><br/><br/><br/>
faith we lost in the team. The fact is that these jovial additions reveal<br/><br/><br/><br/><br/>
PHP version. This is no more damaging than when server sig is left on and<br/><br/><br/><br/><br/>
also by the looks of it, no more difficult to fix.<br/><br/><br/><br/><br/>
<br/><br/><br/><br/><br/>
----- Original Message ----- <br/><br/><br/><br/><br/>
From: "Jimi Thompson" <jimi.thompson (at) gmail (dot) com [email concealed]><br/><br/><br/><br/><br/>
To: "Paul Fierro" <pablo (at) nothing (dot) com [email concealed]><br/><br/><br/><br/><br/>
Cc: <webappsec (at) securityfocus (dot) com [email concealed]><br/><br/><br/><br/><br/>
Sent: Thursday, December 02, 2004 4:35 AM<br/><br/><br/><br/><br/>
Subject: Re: PHP Easter Eggs<br/><br/><br/><br/><br/>
<br/><br/><br/><br/><br/>
> I think the real concern here is that they've put these "hidden little<br/><br/><br/><br/><br/>
> gems" in there in the first place. Since no one else seems to want to<br/><br/><br/><br/><br/>
> come right out and say it, I'll do it. If that's in there, what else<br/><br/><br/><br/><br/>
> is in there that we just haven't found yet?<br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/>
> A photograph of someone's dog in and of itself isn't very threatening.<br/><br/><br/><br/><br/>
> However, when you expect your system and and application to be fairly<br/><br/><br/><br/><br/>
> secure and you find something like this, you have to wonder what else<br/><br/><br/><br/><br/>
> is there that's also not "public".<br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/>
> Does this mean that if I go join up on the PHP developers mailing<br/><br/><br/><br/><br/>
> lists/forums that I can find out about other stuff that might enable<br/><br/><br/><br/><br/>
> me to compromise a widely used e-commerce application like osCommerce?<br/><br/><br/><br/><br/>
> or nukeCommerce? or phpShop? or X-cart? or any of the other scads of<br/><br/><br/><br/><br/>
> both commercial and opensource e-commerce suites that are available.<br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/>
> The only comment I have for the PHP development team is that this is<br/><br/><br/><br/><br/>
> _VERY_ uncool.<br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/>
> 2 cents,<br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/>
> Jimi<br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/>
> On Tue, 30 Nov 2004 12:24:22 -0600, Paul Fierro <pablo (at) nothing (dot) com [email concealed]> wrote:<br/><br/><br/><br/><br/>
> > On 11/30/2004 2:53 AM, exon <exon (at) home (dot) se [email concealed]> wrote:<br/><br/><br/><br/><br/>
> ><br/><br/><br/><br/><br/>
> > > The code should be removed from PHP altogether since it doesn't<br/><br/><br/><br/><br/>
exactly<br/><br/><br/><br/><br/>
> > > provide much in the way of functionality. Possibly php_credits() could<br/><br/><br/><br/><br/>
> > > be added as a function, the way php_info() is now. That way nobody<br/><br/><br/><br/><br/>
could<br/><br/><br/><br/><br/>
> > > glean information unawares, but the info would still be there if you<br/><br/><br/><br/><br/>
> > > need it (and it would be much easier to come by).<br/><br/><br/><br/><br/>
> ><br/><br/><br/><br/><br/>
> > A function named phpcredits() already exists:<br/><br/><br/><br/><br/>
> ><br/><br/><br/><br/><br/>
> > http://www.php.net/phpcredits<br/><br/><br/><br/>
;<br/>
> ><br/><br/><br/><br/><br/>
> > Paul<br/><br/><br/><br/><br/>
> ><br/><br/><br/><br/><br/>
> ><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/>
> -- <br/><br/><br/><br/><br/>
> Thanks,<br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/>
> Jimi

[ reply ]
Re: PHP Easter Eggs Dec 02 2004 04:35AM
Jimi Thompson (jimi thompson gmail com) (3 replies)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
Re: PHP Easter Eggs Nov 30 2004 06:24PM
Paul Fierro (pablo nothing com) (2 replies)
Re: PHP Easter Eggs Dec 02 2004 04:35AM
Jimi Thompson (jimi thompson gmail com) (5 replies)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
I don't think we can speculate what other holes are in there, or how much<br/><br/><br/><br/><br/><br/>
faith we lost in the team. The fact is that these jovial additions reveal<br/><br/><br/><br/><br/><br/>
PHP version. This is no more damaging than when server sig is left on and<br/><br/><br/><br/><br/><br/>
also by the looks of it, no more difficult to fix.<br/><br/><br/><br/><br/><br/>
<br/><br/><br/><br/><br/><br/>
----- Original Message ----- <br/><br/><br/><br/><br/><br/>
From: "Jimi Thompson" <jimi.thompson (at) gmail (dot) com [email concealed]><br/><br/><br/><br/><br/><br
/>
To: "Paul Fierro" <pablo (at) nothing (dot) com [email concealed]><br/><br/><br/><br/><br/><br
/>
Cc: <webappsec (at) securityfocus (dot) com [email concealed]><br/><br/><br/><br/><br/><br
/>
Sent: Thursday, December 02, 2004 4:35 AM<br/><br/><br/><br/><br/><br/>
Subject: Re: PHP Easter Eggs<br/><br/><br/><br/><br/><br/>
<br/><br/><br/><br/><br/><br/>
> I think the real concern here is that they've put these "hidden little<br/><br/><br/><br/><br/><br/>
> gems" in there in the first place. Since no one else seems to want to<br/><br/><br/><br/><br/><br/>
> come right out and say it, I'll do it. If that's in there, what else<br/><br/><br/><br/><br/><br/>
> is in there that we just haven't found yet?<br/><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/><br/>
> A photograph of someone's dog in and of itself isn't very threatening.<br/><br/><br/><br/><br/><br/>

> However, when you expect your system and and application to be fairly<br/><br/><br/><br/><br/><br/>
> secure and you find something like this, you have to wonder what else<br/><br/><br/><br/><br/><br/>
> is there that's also not "public".<br/><br/><br/><br/><br/&g
t;<br/>
><br/><br/><br/><br/><br/><br/>
> Does this mean that if I go join up on the PHP developers mailing<br/><br/><br/><br/><br/><br/>
> lists/forums that I can find out about other stuff that might enable<br/><br/><br/><br/><br/><br/>
> me to compromise a widely used e-commerce application like osCommerce?<br/><br/><br/><br/><br/><br/>
> or nukeCommerce? or phpShop? or X-cart? or any of the other scads of<br/><br/><br/><br/><br/><br/>
> both commercial and opensource e-commerce suites that are available.<br/><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/><br/>
> The only comment I have for the PHP development team is that this is<br/><br/><br/><br/><br/><br/>
> _VERY_ uncool.<br/><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/><br/>
> 2 cents,<br/><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/><br/>
> Jimi<br/><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/><br/>
> On Tue, 30 Nov 2004 12:24:22 -0600, Paul Fierro <pablo (at) nothing (dot) com [email concealed]> wrote:<br/><br/><br/><br/><br/><br/>
> > On 11/30/2004 2:53 AM, exon <exon (at) home (dot) se [email concealed]> wrote:<br/><br/><br/><br/><br/><br/>
> ><br/><br/><br/><br/><br/><br/>
> > > The code should be removed from PHP altogether since it doesn't<br/><br/><br/><br/><br/><br/>
exactly<br/><br/><br/><br/><br/><br/>
> > > provide much in the way of functionality. Possibly php_credits() could<br/><br/><br/><br/><br/><br/>
> > > be added as a function, the way php_info() is now. That way nobody<br/><br/><br/><br/><br/><br/>
could<br/><br/><br/><br/><br/><br/>
> > > glean information unawares, but the info would still be there if you<br/><br/><br/><br/><br/><br/>
> > > need it (and it would be much easier to come by).<br/><br/><br/><br/><br/><br/>
> ><br/><br/><br/><br/><br/><br/>
> > A function named phpcredits() already exists:<br/><br/><br/><br/><br/><br/>
> ><br/><br/><br/><br/><br/><br/>
> > http://www.php.net/phpcredits<br/><br/><br/><br/>
;<br/>
;<br/><br/>
> ><br/><br/><br/><br/><br/><br/>
> > Paul<br/><br/><br/><br/><br/><br/>
> ><br/><br/><br/><br/><br/><br/>
> ><br/><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/><br/>
> -- <br/><br/><br/><br/><br/><br/>
> Thanks,<br/><br/><br/><br/><br/><br/>
><br/><br/><br/><br/><br/><br/>
> Jimi

[ reply ]
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
I don't think we can speculate what other holes are in there, or how much<br/><br/><br/><br/><br/><br/><b
r/>
faith we lost in the team. The fact is that these jovial additions reveal<br/><br/><br/><br/><br/><br/>
<br/>
PHP version. This is no more damaging than when server sig is left on and<br/><br/><br/><br/><br/><br/><br
/>
also by the looks of it, no more difficult to fix.<br/><br/><br/><br/><br/><br/><b
r/>
<br/><br/><br/><br/><br/><br/><br/>
----- Original Message ----- <br/><br/><br/><br/><br/><br/><br/>
From: "Jimi Thompson" <jimi.thompson (at) gmail (dot) com [email concealed]><br/><br/><br/><br/><br/><
;br<br/>
/><br/>
To: "Paul Fierro" <pablo (at) nothing (dot) com [email concealed]><br/><br/><br/><br/><br/><
;br<br/>
/><br/>
Cc: <webappsec (at) securityfocus (dot) com [email concealed]><br/><br/><br/><br/><br/><
;br<br/>
/><br/>
Sent: Thursday, December 02, 2004 4:35 AM<br/><br/><br/><br/><br/><br/><br/
>
Subject: Re: PHP Easter Eggs<br/><br/><br/><br/><br/><br/><b
r/>
<br/><br/><br/><br/><br/><br/><br/>
> I think the real concern here is that they've put these "hidden little<br/><br/><br/><br/><br/><br/>
<br/>
> gems" in there in the first place. Since no one else seems to want to<br/><br/><br/><br/><br/><br/><br/
>
> come right out and say it, I'll do it. If that's in there, what else<br/><br/><br/><br/><br/><br/><b
r/>
> is in there that we just haven't found yet?<br/><br/><br/><br/><br/><br/><b
r/>
><br/><br/><br/><br/><br/><br/><b
r/>
> A photograph of someone's dog in and of itself isn't very threatening.<br/><br/><br/><br/><br/><b
r/><br/>
<br/>
> However, when you expect your system and and application to be fairly<br/><br/><br/><br/><br/><br/>
<br/>
> secure and you find something like this, you have to wonder what else<br/><br/><br/><br/><br/><br/><b
r/>
> is there that's also not "public".<br/><br/><br/><br/><br/&a
mp;g<br/>
t;<br/><br/>
><br/><br/><br/><br/><br/><br/><b
r/>
> Does this mean that if I go join up on the PHP developers mailing<br/><br/><br/><br/><br/><br/>
;<br/>
> lists/forums that I can find out about other stuff that might enable<br/><br/><br/><br/><br/><br/>
<br/>
> me to compromise a widely used e-commerce application like osCommerce?<br/><br/><br/><br/><br/><br
/><br/>
> or nukeCommerce? or phpShop? or X-cart? or any of the other scads of<br/><br/><br/><br/><br/><br/><br/
>
> both commercial and opensource e-commerce suites that are available.<br/><br/><br/><br/><br/><br/
><br/>
><br/><br/><br/><br/><br/><br/><b
r/>
> The only comment I have for the PHP development team is that this is<br/><br/><br/><br/><br/><br/><br/
>
> _VERY_ uncool.<br/><br/><br/><br/><br/><br/>
;<br/>
><br/><br/><br/><br/><br/><br/><b
r/>
> 2 cents,<br/><br/><br/><br/><br/><br/>
<br/>
><br/><br/><br/><br/><br/><br/><b
r/>
> Jimi<br/><br/><br/><br/><br/><br/><b
r/>
><br/><br/><br/><br/><br/><br/><b
r/>
><br/><br/><br/><br/><br/><br/><b
r/>
> On Tue, 30 Nov 2004 12:24:22 -0600, Paul Fierro <pablo (at) nothing (dot) com [email concealed]> wrote:<br/><br/><br/><br/><br/><br/>
<br/>
> > On 11/30/2004 2:53 AM, exon <exon (at) home (dot) se [email concealed]> wrote:<br/><br/><br/><br/><br/><br/>
<br/>
> ><br/><br/><br/><br/><br/><br/><b
r/>
> > > The code should be removed from PHP altogether since it doesn't<br/><br/><br/><br/><br/><br
/><br/>
exactly<br/><br/><br/><br/><br/><br/>
;<br/>
> > > provide much in the way of functionality. Possibly php_credits() could<br/><br/><br/><br/><br/><br/><
br/>
> > > be added as a function, the way php_info() is now. That way nobody<br/><br/><br/><br/><br/><br/>
<br/>
could<br/><br/><br/><br/><br/><br/><
br/>
> > > glean information unawares, but the info would still be there if you<br/><br/><br/><br/><br/><br/><br
/>
> > > need it (and it would be much easier to come by).<br/><br/><br/><br/><br/><br/><b
r/>
> ><br/><br/><br/><br/><br/><br/><b
r/>
> > A function named phpcredits() already exists:<br/><br/><br/><br/><br/><br/>
;<br/>
> ><br/><br/><br/><br/><br/><br/><b
r/>
> > http://www.php.net/phpcredits<br/><br/><br/><br/>
;<br/>
;<br/><br/>
;<br/><br/><br/>
> ><br/><br/><br/><br/><br/><br/><b
r/>
> > Paul<br/><br/><br/><br/><br/><br/><b
r/>
> ><br/><br/><br/><br/><br/><br/><b
r/>
> ><br/><br/><br/><br/><br/><br/><b
r/>
><br/><br/><br/><br/><br/><br/><b
r/>
><br/><br/><br/><br/><br/><br/><b
r/>
> -- <br/><br/><br/><br/><br/><br/><br/>
> Thanks,<br/><br/><br/><br/><br/><br/>
;<br/>
><br/><br/><br/><br/><br/><br/><b
r/>
> Jimi

[ reply ]
Re: PHP Easter Eggs Dec 02 2004 04:35AM
Jimi Thompson (jimi thompson gmail com) (3 replies)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com) (5 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
RE: SQL injection (no single quotes used) Dec 15 2004 10:25AM
Mutallip Ablimit (mutax insi co jp) (2 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 11:20PM
PD9 Software (info pd9soft com)
Re: SQL injection (no single quotes used) Dec 15 2004 02:49AM
Olivier G. Gaumond (olig monimap com) (1 replies)
Re: SQL injection (no single quotes used) Dec 15 2004 04:50PM
Juan Carlos (johnccr yahoo com) (1 replies)
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: SQL injection (no single quotes used) Dec 14 2004 07:30PM
Adam Tuliper (amt gecko-software com)
Re: PHP Easter Eggs Dec 02 2004 04:32PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
Re: PHP Easter Eggs Nov 29 2004 04:04PM
Griffiths, Ian (ian griffiths liv-coll ac uk)
Re: Fwd: PHP Easter Eggs Nov 29 2004 03:43PM
Astarna (mailing astarna com)







 

Privacy Statement
Copyright 2009, SecurityFocus