|
php functions -
08-31-2006, 12:06 PM
To get back to some uniformity on servers php.ini disable functions were syncronized. If this has an effect on your particular php script let us know. We have a couple layers protecting php functions and can scale back slightly on some of them, but would rather make the scale back adjustements as needed depending on the risk, per server.
These are the disabled functions. Some servers had them all and ran fine, some had as little as 1.
exec,passthru,proc_open,readfile,proc_close,shell_ exec,system,popen,curl_exec
I hate to keep harping on security and causing inconvenience to some scripts that ran great for years - except that many of those scripts have inherent flaws and are now getting hacked at an exponential rate. Sites that report and track this (zone-h et.al.) can no longer keep up just counting the defacements. You only need to ask someone who's site was defaced and/or hacked & used for a phishing scam which way, in hindsight, would have been more of an inconvenience.
1.) Closing a hole in advance. Adjusting a site or two to that change.
or
2.) Losing all sites and email completely, cleaning up a major mess, suffering lost data, watching your customer base abandon you, and enduring several days of the sites being offline while you work 20 hr days to get it fixed. Wondering when it will happen again.
|