WebApp Sec mailing list archives

RE: PHP Easter Eggs


From: Krul Thomas <Thomas.Krul () psepc-sppcc gc ca>
Date: Mon, 29 Nov 2004 11:19:41 -0500

I think you must have the "expose_php" value in your php.ini set to ON in
order for this to work.

-----Original Message-----
From: Andi McLean [mailto:andi_mclean () ntlworld com] 
Sent: Sunday, November 28, 2004 8:22 AM
To: webappsec () securityfocus com
Subject: Fwd: PHP Easter Eggs


Hi,

Does anyone know about the easter eggs in PHP?
I've just found out about them, My trust in PHP has just had a major set
back, 
as I'm wondering what other easter eggs there are and can any be used to 
circumenvent the protection I have on my site.
I feel like I now need to have a look at the source code, to find out what 
else is there.

<anywebsite.that/uses.php>?=PHPE9568F36-D428-11d2-A769-00AA001ACF42

<anywebsite.thatuses.php>?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000

<anywebsite.thatuses.php>?=PHPE9568F34-D428-11d2-A769-00AA001ACF42

eg www.jsane.com/index.php?=PHPE9568F36-D428-11d2-A769-00AA001ACF42
www.jsane.com/index.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000
www.jsane.com/index.php?=PHPE9568F34-D428-11d2-A769-00AA001ACF42


Andi


Current thread: