📜 ⬆️ ⬇️

Ability to get information about the site on symfony

In the dev environment, symfony by default gives a lot of debugging information. Talks about the server, displays the used configurations, shows queries to the database and versions of the components used. And, having this information, you can find out about the vulnerabilities of the site or to look for logins / passwords / access parameters specified in the settings (but not the database).

Because open project, you can view the status of the code for any version and see the vulnerabilities in the bugtracker.

Search results: Yandex , Google . Examples - poehali.org , pallada.ru .
')
The news does not claim to be new or original. Lord, be careful and use. /symfony project:deploy (did anyone run this on Windows?) with rsync_exclude: *_dev.php

Source: https://habr.com/ru/post/76831/


All Articles