|
From: Hamid H. <ha...@mo...> - 2006-01-08 21:23:10
|
Hi ,
I am using Webmin and Virtualmin for fedora core 4 and installed apache
2.0.54 and php 5.0.4.
When I was surfing the hosts and tried one of the hosts info.php which
contains phpinfo() function to see if everythings working fine that host
on virtualmin or not and saw something interesting in PHP Variables
section of phpinfo() !!
I saw some $_ENV variables which contains some information about the
webmin and virtualmin even some passwords of virtualmin !!!!
here is some example about these variables :
_ENV["DOCUMENT_REALROOT"] /usr/libexec/webmin
_ENV["VIRTUALSERVER_MAILBOXLIMIT"] 20
_ENV["VIRTUALSERVER_LOGROTATE"] 1
_ENV["VIRTUALSERVER_PREFIX"] xxxxxxxxx ( I changed this !)
_ENV["VIRTUALSERVER_IP"] xx.xx.xx.xx ( this too ! )
_ENV["QUOTA_SBLOCKS"] 10240
_ENV["HTTP_CONTENT_LENGTH"] 436
_ENV["VIRTUALSERVER_LIMIT_WEB"] 1
_ENV["QUOTA_FILESYS"] /home
_ENV["VIRTUALSERVER_GID"] 538
_ENV["MINISERV_CONFIG"] /etc/webmin/miniserv.conf
_ENV["VIRTUALSERVER_POSTGRES"] /no value/
_ENV["VIRTUALSERVER_MAIL"] 1
_ENV["QUOTA_HFILES"] 0
and a lot of other variables which is really secure ! I don't know from
where phpinfo() found these but I need to solve this problem ASAP ! Also
I checked the same issue on another server and the same result happened
! any idea ?
--
Regards
=================================================================
/ Seyyed Hamid Reza / WINDOWS FOR NOW !! /
/ Hashemi Golpayegani / Linux for future , FreeBSD for ever /
/ Morva System Co. / ------------------------------------- /
/ Network Administrator/ ha...@mo... , ICQ# : 42209876 /
================================================================
|