NamePros
Welcome, Guest! Ready to make a name for yourself in the domain business? We welcome both the hobbyist and professional domainer to join the discussion as part of the NamePros community.

Click here to create your profile to start earning reputation for posting, and trader ratings for buying & selling in our free e-marketplace. Build your trader rating with each successful sale. Our system has tracked over 100,000 sales and counting!
FAQ & TOS Register Search Today's Posts Mark Forums Read

Go Back   NamePros.com > Website Development Discussion Forums > Programming
Reload this Page How to secure your php.ini

Programming PHP, Perl, Ruby on Rails, AJAX, HTML, XHTML, CSS, JavaScript, MySQL and any other coding topics.

Advanced Search


Closed Thread
 
LinkBack Thread Tools
Old 07-09-2005, 12:01 PM THREAD STARTER               #1 (permalink)
Senior Member
Join Date: Oct 2004
Posts: 1,201
vimkar is a name known to allvimkar is a name known to allvimkar is a name known to allvimkar is a name known to allvimkar is a name known to allvimkar is a name known to allvimkar is a name known to allvimkar is a name known to all
 



How to secure your php.ini


Here are a few tips of how to secure your php.ini !

Edit our php.ini by logging into shell with root :

pico /usr/lib/php.ini

And change the line:

disable_functions =
to:
disable_functions = exec, shell_exec, system, passthru

another thing you could change is

safe_mode = Off
to
safe_mode = On


another thing you could disable is
enable_dl=On
change to
enable_dl=Off
__________________
Forex Trading Information
vimkar is offline  
Old 07-09-2005, 12:31 PM   #2 (permalink)
Senior Member
 
Porte's Avatar
Join Date: May 2005
Location: I'm right here
Posts: 3,526
Porte has much to be proud ofPorte has much to be proud ofPorte has much to be proud ofPorte has much to be proud ofPorte has much to be proud ofPorte has much to be proud ofPorte has much to be proud ofPorte has much to be proud ofPorte has much to be proud of
 



I run php on my local pc small server, so thanks for these tips. Just if you could explain to me further about each function, and why it should be changed. Thanks
__________________
WP Theme Developer
Your One-stop for Premium Magazine/CMS WordPress Themes
Deluxe Themes
Porte is offline  
Old 07-09-2005, 03:46 PM   #3 (permalink)
NamePros Expert
 
Peter's Avatar
Join Date: Nov 2003
Location: Scotland
Posts: 5,069
Peter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond repute
 


Child Abuse Save The Children Save The Children Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009
disable_functions stops php from being able to carry out these functions within a script http://uk.php.net/features.safe-mode (about 1/4 of the way down)

changing enable_dl to off stops php from loading any extra modules http://uk2.php.net/dl

enabling safe_mode changes some functionality of php for example when not in safe mode you can edit a file anywhere on the server, when safe_mode is on you can only write to files within a certain tree http://uk.php.net/features.safe-mode
Peter is offline  
Old 07-11-2005, 12:06 AM   #4 (permalink)
NamePros Member
Join Date: May 2005
Posts: 86
dejaone is an unknown quantity at this point
 



thanks for the useful tips. I just setup my own php.ini on a shared server.
__________________
Add to 100 Directories fast and get 50 one-way links
Build natural, one-way and permanent links that actually work
dejaone is offline  
Old 07-11-2005, 03:55 AM   #5 (permalink)
NamePros Member
Join Date: Oct 2003
Posts: 126
i386 is an unknown quantity at this point
 



If you have a shared server, I assume ini_set() could be used.
i386 is offline  
Old 07-11-2005, 05:31 AM   #6 (permalink)
NamePros Expert
 
Peter's Avatar
Join Date: Nov 2003
Location: Scotland
Posts: 5,069
Peter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond repute
 


Child Abuse Save The Children Save The Children Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009
as long as the host has not disabled the function, if you have htaccess access on your server then some of the options that are pointless changing in your script can be changed in this file.
Peter is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Need HELP with SSL (Secure Certificate) Gene Web Design Discussion 11 06-24-2005 09:23 AM
Purchase Verification from Name Secure taheny Domain Newbies 6 10-27-2004 10:15 AM
Secure Hosting - $19.95/year Great Budget Hosting invnet Web Hosting Offers 0 03-22-2004 10:30 AM
Shopping Cart / Secure CC checkout kydlynx Programming 12 07-15-2003 02:23 AM

Liquid Web Smart Servers  
All times are GMT -7. The time now is 09:25 AM.

Managed Web Hosting by Liquid Web
Domain name forum recommended by Domaining.com Powered by: vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 Ad Management plugin by RedTyger