Koozali.org: home of the SME Server

Security Concern?

Offline spider_01

  • 6
  • +0/-0
Security Concern?
« on: September 14, 2004, 07:31:12 AM »
I installed SME 6.0.1-01 this weekend. (I was running 5.6 since its release). Tonight, i ran a phpinfo() script and discovered my username and password were visible under php variables. (PHP_AUTH_USER and PHP_AUTH_PW). I have never seen this on any server I have run this script on, including SME 5.6. I'm definately no security expert and still consider myself as a linux newbie but this feels like a security risk to me. Should I be conceren. What can I do to hide this?
Steve

RavenIV

Security Concern?
« Reply #1 on: September 15, 2004, 02:33:09 AM »
send this report to staff_AT_contribs.org.
maybe it is a security-hole...

cheers