Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Update of the php.ini-paranoid example file (was Re: ping22: can not kill this process)

From: Javier Fernández-Sanguino Peña <jfs(at)computer.org>
Date: Mon Jan 07 2008 - 18:16:05 EST


On Fri, Jan 04, 2008 at 12:41:55PM -0600, Raphael Geissert wrote:
> Rick Moen wrote:
> >
> > disable_functions = dl, phpinfo, system, mail, include, shell_exec, exec,
>
> include()? I don't want to imagine how many scripts will break.

You are right, I have removed this from the list. The use of 'include' is really common on applications.

Actually, the php.ini-paranoid file was created in october 2004 and has not been ammended since. I have reviewed the file to updated it with the latest PHP5 release php.ini-dist contents and have also added new values (and details) which were not available in the previous version.

Attached is the latest version of this configuration file I have concocted. I would appreciate if people running PHP applications could test it out and comment on it. As I've said before (and now the script documents that too) is easy to see the differences with the one provided in standard Debian installations by diffing it.

Hope that helps.

Javier

-- 
To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Mon Jan 7 18:17:48 2008
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:55:05 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library