Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-05-14, 23:20:17

Author Topic: php.ini file path to disable php functions for security  (Read 4270 times)

0 Members and 1 Guest are viewing this topic.

Offline befree22

  • Valuable Member
  • *
  • Posts: 95
  • Karma: +0/-1
    • View Profile
Disable php functions for security

I read the 2 articles below about dangerous php functions and how to disable them.

http://stackoverflow.com/questions/1865020/php-how-to-disable-dangerous-functions
http://www.cyberciti.biz/faq/linux-unix-apache-lighttpd-phpini-disable-functions/

Could someone tell me which php.ini file I need to add the following code to inside Kloxo-MR?

Here's the code I want to add to the correct php.ini file:

Code: [Select]
disable_functions =exec,passthru,shell_exec,system,proc_open,popen,curl_exec,curl_multi_exec,parse_ini_file,show_source
Code: [Select]
allow_url_fopen=Off
allow_url_include=Off

FYI: I have a php.ini file that shared hosting provider added to the root folder of my Wordpress but I doubt this is the correct location in Kloxo-MR. The web hosted added the wrong code to the php.ini and I only noticed it today.

Thanks

Offline sIiiS

  • Valuable Member
  • *
  • Posts: 71
  • Karma: +0/-0
    • View Profile
Re: php.ini file path to disable php functions for security
« Reply #1 on: 2014-01-26, 07:54:02 »
no need to edit your php.ini

go to your panel, click on "Advanced PHP Configure" and in this form you can see "Disable Functions" ... so disable anythings you need !

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: php.ini file path to disable php functions for security
« Reply #2 on: 2014-01-26, 19:35:47 »
Not if using php-fpm, per domain/client advanced php doesn't work.  If you edit it as admin, it will edit the correct one, and set it server wide.

Eitherway, to answer your question.  /etc/php.ini

;)
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

 


MRatWork Affiliates:    BIGRAF(R) Inc.    House of LMAR    EFARgrafix
Click Here

Page created in 0.079 seconds with 22 queries.

web stats analysis