From 84123a692a8c9e84a8c41f0701aa040010216387 Mon Sep 17 00:00:00 2001 From: Roger Pueyo Centelles Date: Thu, 14 Dec 2017 19:22:31 +0100 Subject: [PATCH] Disable phpinfo and serverinfo calls (fixes issue #6) --- index.php | 37 ++++++++++++++++++++++--------------- 1 file changed, 22 insertions(+), 15 deletions(-) diff --git a/index.php b/index.php index 4d53d10..848fb25 100644 --- a/index.php +++ b/index.php @@ -115,21 +115,28 @@ function getHelp() { switch ($service) { - case 'version': - header("Content-Type: text/plain"); - echo $VERSION; - exit; - case 'help': - header("Content-Type: text/plain"); - getHelp(); - break; - case 'phpinfo': - echo phpinfo(); - break; - case 'serverinfo': - echo getServerInfo(); - break; default: - call_service($service); + case 'version': + header("Content-Type: text/plain"); + echo $VERSION; + exit; + case 'help': + header("Content-Type: text/plain"); + getHelp(); + break; + case 'phpinfo': + //echo phpinfo(); + //break; + case 'serverinfo': + //echo getServerInfo(); + //break; + case 'disabled': + echo "This call is disabled for security reasons. " . + "See " . + "https://github.com/guifi/snpservices/issues/6 " . + "for more details."; + break; + default: + call_service($service); }