How To Secure Your Php.ini File  Safe Mode ; Disable_functions ; Etc
			Jun 11, 2007
				what are the most important issues for secure php.ini file like when you turn your SAFE_MODE ON or OFF?
or please who every read this topic to post his important disable_functions in php.ini ... and if some functions disable to post it ...
let's make this subject for the most important issues for secure your php.ini 
from script-kids as we can ...
here i have some important question's for anyone has or controlling a server ; vps  ....
 #0x01 ; what the most important disable_functions for the php.ini?
 #0x02 ; is the safe_mode should be enabled? or disable? and this depend on what exacly?
 #0x03 ; what the functions or any trick to control the nobody ( attacker on the server or shell ) FROOZ .... didn't move ? or make any command in the server ...
 #0x04 ; i saw in some secure server ( as they say ) they changed the Server : discribe to them name[s] like 
Server : SECURE BY US .COM OR SECURE SERVER ..
uname -a : Linux secure.secure.com 2.6.9-023stab040.1 #1 Mon Jan 15 23:24:32 MSK 2007 i686 athlon i386 GNU/Linux
 sysctl : linux 2.6.9-023stab040.1
 Server : SECURE BY US ! < [THIS WHAT I MEAN HOW COULD WE CHANGE IT IN PHP.ini ?]
 id :     uid=99(nobody) gid=99(nobody) groups=99(nobody) <[how can we cannot make this nobody to have the host id ! everyhost in the server should have his own name and php.ini ?]
 pwd : /home/host/public_html/
#0x05 ;  how can we hide the uname -a on the shell [ the attacker upload it to our customer site !] 
 #0x06 ; how can we hide the sysctl to view to anyone like [ attacker ] ...
 #0x07 ; how can we rewrite on he Server Type the display for our secure message?Server : SECURE BY US ! 
#0x08 ; how can we give evey site and customer his php.ini file in his public_html? and how can we give him [ JUST HIS PERMISSION TO HIS SITES FOLDER AND NOT OTHER PATHS AND PERMISSION!]
these question every one had a server ; vps , need to know and secure his box from other ...
and anyone would like to publish any new [secure or not] idea please let us know what you would like to say ....
	
	View 1 Replies
  
    
		
ADVERTISEMENT
    	
    	
        Jan 31, 2007
        i have vps and i enable the safe_mode , but now i need to turn it off becouse i need to install image uploader script and this script need safe mode off to work
 
so,
 
what can i do to secure my server while i turn off my safe mode?
what can happend if i turn off safe mode?
what is the job of safe mode?
	View 6 Replies
    View Related
  
    
	
    	
    	
        Nov 6, 2009
        What is the best option in the php setting does keeping the php function safe mode on or off?
	View 12 Replies
    View Related
  
    
	
    	
    	
        Apr 9, 2009
        i need to enable php safe mode on for my joomla and i came across this
Quote:
When the php safe mode is turned off globally by default at our server end, you can still override the setting to turn it ON for only your domain by just insert the following line inside the ".htaccess" file (at Linux server):
Code:
php_value safe_mode "1"
my joomla .htaccess file:
Quote:
##
# @version $Id: htaccess.txt 10492 2008-07-02 06:38:28Z ircmaxell $
# @package Joomla
# @copyright Copyright (C) 2005 - 2008 Open Source Matters. All rights reserved.
# @license http://www.gnu.org/copyleft/gpl.html GNU/GPL
# Joomla! is Free Software
##
#####################################################
#  READ THIS COMPLETELY IF YOU CHOOSE TO USE THIS FILE
#
# The line just below this section: 'Options +FollowSymLinks' may cause problems
# with some server configurations.  It is required for use of mod_rewrite, but may already
# be set by your server administrator in a way that dissallows changing it in
# your .htaccess file.  If using it causes your server to error out, comment it out (add # to
# beginning of line), reload your site in your browser and test your sef url's.  If they work,
# it has been set by your server administrator and you do not need it set here.
#
#####################################################
##  Can be commented out if causes errors, see notes above.
Options +FollowSymLinks
#
#  mod_rewrite in use
RewriteEngine On
########## Begin - Rewrite rules to block out some common exploits
## If you experience problems on your site block out the operations listed below
## This attempts to block the most common type of exploit `attempts` to Joomla!
#
# Block out any script trying to set a mosConfig value through the URL
RewriteCond %{QUERY_STRING} mosConfig_[a-zA-Z_]{1,21}(=|\%3D) [OR]
# Block out any script trying to base64_encode crap to send via URL
RewriteCond %{QUERY_STRING} base64_encode.*(.*) [OR]
# Block out any script that includes a <script> tag in URL
RewriteCond %{QUERY_STRING} (<|%3C).*script.*(>|%3E) [NC,OR]
# Block out any script trying to set a PHP GLOBALS variable via URL
RewriteCond %{QUERY_STRING} GLOBALS(=|[|\%[0-9A-Z]{0,2}) [OR]
# Block out any script trying to modify a _REQUEST variable via URL
RewriteCond %{QUERY_STRING} _REQUEST(=|[|\%[0-9A-Z]{0,2})
# Send all blocked request to homepage with 403 Forbidden error!
RewriteRule ^(.*)$ index.php [F,L]
#
########## End - Rewrite rules to block out some common exploits
	View 3 Replies
    View Related
  
    
	
    	
    	
        Aug 30, 2008
        I have a script that needs safe mode off to run, the script writers have said safe mode is disabled as default and not required and even disabled in php 6
 
Now I'm not to fimular with Safe mode, all I know is most scripts are wrote to work with this on
	View 4 Replies
    View Related
  
    
	
    	
    	
        Jun 3, 2008
        Should i switch safe mode on or off . Right now i am using it as on some one told me if i switch it off then server can easily hack but becoz i switch it on im having too much problem specially users of sites having problem of uploading and wordpress also have issue and some more script what you say what should i do?
	View 9 Replies
    View Related
  
    
	
    	
    	
        May 13, 2007
        how can i make "safe mode on/off" using .htaccess?( in SharedHosting )
	View 1 Replies
    View Related
  
    
	
    	
    	
        Nov 27, 2007
        I would like to know as to whether or not you have php safe mode turned on? If you do, please specify why, and would you allow your clients to turn it off?
	View 13 Replies
    View Related
  
    
	
    	
    	
        Sep 17, 2007
        I searched but couldn't find much - should you run PHP with safe mode on or off on a shared (Linux) server?
	View 3 Replies
    View Related
  
    
	
    	
    	
        Aug 2, 2008
        i have a cpanel server.. can any one tell me how to allow safe mode to a specific domain?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Jan 18, 2008
        I am going to run a free host, yes I know I should post this in FWHT but well, they dont answer very fast if at all.
 
It is very dangerous to have Safe Mode OFF on a free host, but someone was telling me about open_basedir, which makes it so they cant touch any files set outside of open_basedir. Would this be suffiecient to keep them from touching others files? I know I need to disable other functions like exec() and stuff but would open_basedir keep hackers away from others files and hacking them... 
	View 7 Replies
    View Related
  
    
	
    	
    	
        Aug 11, 2008
        To Install www.awbs.com scripts to my server 
How Can I Do This Following to one site on My server
safe_mode Off
allow_url_fopen On
session.auto_start Off
tell Me that i can do that from httpd config
	View 4 Replies
    View Related
  
    
	
    	
    	
        Oct 2, 2007
        I have found on one webhost that they have very cool feature:
Here is what they say:
Quote:
Browsing through any webhost related forum will reveal that giving safe mode  off poses extreme security risk to the server. Because it offers hackers a  great advantage to access any other members account or read their sensitive  files which usually contain passwords.
But then some genuine scripts won't work with safe mode ON. Meaning you could turn it on per member requests but that takes lots of labor.
So we completely reprogrammed the safe mode PHP source code and recompiled it. As a result ours safe mode OFF is light-years safer & hacker-proof then standard PHP v5 safe mode ON.
So all our members are getting safe mode OFF, with harder security then those hosts who offer Safe Mode ON.
So now I am wondering, how they did that? I have searched forums and Google for lots of different keyword but haven't found anything. 
I believe a lot of you running Apache as nobody and having php save mode OFF. It there any way you protect yourself? phpsuexec is not a solution now as it increasing load.
	View 8 Replies
    View Related
  
    
	
    	
    	
        Jul 25, 2009
        I've recently upgraded from Shared hosting to a VPS.  I'm currently getting my new VPS setup before migrating my site over.  On my shared server, both the global and local safe_mode directives were reported as off by php_infO(). On ym new server, the global is reported as off, but local is reported as on.
On my old server, the PHP was version 4.4.9 running as a CGI. On my new server, PHP 5.1.6 is running as an Apache 2.0 Handler.
I have already set safe_mode to off in my global php.ini file (hence why global is reported by off).  However, I have no local php.ini files, htaccess files, or php directive settings in place, so I cannot figure out why local is set to on!
I've tried editing httpd.conf to include "php_admin_flag safe_mode Off", though I'm not certain I put it in the right place.  There is only one website on this server.
With the CGI php on my old server, I was able to create a local php.ini file to overwrite global directives, but that seems to have no effect with the Apache Handler on my new server.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Mar 8, 2008
        I decided to apply PHP safe mode to my servers, considering:
- I cannot prohibit using exec functions (some binary uses are needed, like host, mysqldump, etc..)
- I cannot restrict at all via UID/GID method at bins due to several problems..
Safe mode is the final sollution, as I only need "safe_mode_exec_dir" config to set a folder with the necesary binaries... this will stop nobody user (Apache) to exec whatever it wants, like perl, binaries uploaded to an public insecure folder (exploits), or anything else... people only could exec() the binaries I want and where I want. This will stop finally 95% of my hack problems.
Well. The problem is safe_mode is enabled or not, but you cannot set o disable certain features of this safe mode, like UID/GID checks (*******!)...
I am trying to configure so only "safe_mode_exec_dir" would apply, so:
- Including UIDs checks disabled by:
safe_mode_include_dir = "/home/"
(tested)
- Some variables set to NULL, as safe_mode_allowed_env_vars or safe_mode_protected_env_vars...
- safe_mode_exec_dir = "/usr/phpbin/"
Great! with symbolic lynks in... the best sollution available for me.
- open_basedir = "/home/"
(for fopen, etc...)
Ok ok.. but problems there.. by example this one:
Quote:
Warning: fopen() [function.fopen]: SAFE MODE Restriction in effect. The script whose uid is 32015 is not allowed to access cache/dynamic_fields/modules.php owned by uid 99 in /home/yyyyyyyyy/public_html/chn/modules/DynamicFields/DynamicField.php on line 823
Great.. fopen is under UID/GID checks, but it is not an include, so safe_mode_include_dir would not apply...
Now fopen, link, unlink, etc.. functions are UID restricted and this seems to be impossible to disable.... pffffffff...
can you share your safe_mode configs or sollutions for this problem?
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jan 25, 2007
        I moved to a new didecated server, after moving some secripts don't work any more like : php upload center that change the photo name and write the site name under the photo. when I try to upload any image the page reload without any result nor errors!
when I took a look to the php info I found many fanctions are disable.
Now I don't know which function is the one which couse this problem.
disable_functions:
Code:
dl,exec,shell_exec,system,passthru,popen,pclose,proc_open,proc_nice,proc_terminate,proc_get_status,proc_close,pfsockopen,leak,apache_child_terminate,posix_kill,posix_mkfifo,posix_setpgid,posix_setsid,posix_setuid,escapeshellcmd,escapeshellarg,dl,exec,shell_exec,system,passthru,popen,pclose,proc_open,proc_nice,proc_terminate,proc_get_status,proc_close,pfsockopen,leak,apache_child_terminate,posix_kill,posix_mkfifo,posix_setpgid,posix_setsid,posix_setuid,escapeshellcmd,escapeshellarg
my php Version 4.4.4
	View 7 Replies
    View Related
  
    
	
    	
    	
        Jan 15, 2009
        Does anyone know of a CDN that can provide secure file delivery for 100+ people? I'm looking for something that will allow me to send product download links to customers and have them only download the files once each. They mustn't be able to view or distribute the actual file location for their friends to download.
I'm looking for a pay as you go service with no sign up fee.
I know simpleCDN offers pay as you go, at a rate of $0.09 per GB with no sign up fee, but they only seem to offer http and https delivery at present, which is half way there, but it lacks the secure delivery.
I know Edgecast offers a 'secure token' system that allows download links to be sent out that can only be used once. However, they have a whopping $550 sign up fee, and then a whopping $550 per TB transferred. This has the secure delivery, but lacks the pricing my company can afford.
Does anyone know of any more CDNs that have this secure download link function? 
The 'secure token' functionality of Edgecast is a good idea, but even a CDN that just allows you the standard function of creating multiple FTP accounts with different permissions will do to trick.
	View 1 Replies
    View Related
  
    
	
    	
    	
        Jan 21, 2008
        I am running a large scale business and some time I have to transfer large and very important data files to my business partner. I fear about my data because there are many of my business competitors who will definitely try to steal my important data. So there is huge amount of risk involved in sharing my important data on Internet. I recently heard about secure file transfer technique from my friend who is working in well established software company. Does anyone have any idea about what is Secure File Transfer (SFT) service and how does it work?
	View 2 Replies
    View Related
  
    
	
    	
    	
        Feb 9, 2009
        I don't know where to ask this question so hopefully I'm in the right forum. I have a friend that owns his own company and travels alot. He needs a place where he can store his work files (mostly document like word, excel, pdf, drawings, etc...) which contains very sensitive information. He need a place where he or the people in his team can transfer files and that he can setup access levels for his users. He need access to his files with a secure tool such as sftp or something else that you guys can recommend. 
Also, since some files can be very large he requires a good transfer speed from everywhere in the world. He's looking at around 100GB of storage space and a very high transfer allowance. He will probably need to host his website also. Do you guys think it's better to host the files and website separately?
	View 3 Replies
    View Related
  
    
	
    	
    	
        Feb 13, 2008
        I deleted my tmp folder and mounted a secure tmp file via fstab  
e.g. 
/path/to/tmp /tmp  ext2   loop,noexec,nosuid,rw  0 0
the temp files are now written to a secure tmp file, however some processes still need that folder for example cpanel.
"Failed to create directory /tmp/cpanel.TMP.xxxxx"
Should I ignore that and similar error messages or what am I supposed to do?
	View 8 Replies
    View Related
  
    
	
    	
    	
        Feb 10, 2015
        I'm build Plesk Panel for Linux and Presence Builder, I don't want my user can upload their website to hosting via File Manager. How can I do it...
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jul 6, 2009
        My /tmp on my cPanel hosting server is nearly full, and I was wondering if it is safe to remove all the contents in /tmp, if not, what can I delete to clear up the space?
	View 6 Replies
    View Related
  
    
	
    	
    	
        Feb 15, 2008
        Most of my files are 755 as permission. Is this safe?
How about putting all files under 644 permission? What is the best permission so that all files are safe from intrusion?
	View 8 Replies
    View Related
  
    
	
    	
    	
        May 12, 2007
         I'm a customer and don't know much about server management, so like title says, is it okay to put php.ini in public_html?
	View 14 Replies
    View Related
  
    
	
    	
    	
        Dec 18, 2007
        how to know in which mode php running ? CGI or ISAPI
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jun 21, 2009
        I am trying to install gallery 2.3 and it requires exec() to be enabled for some functions. Is it safe to enable it in php.ini?
In php.ini file I see this, disable_functions = symlink,shell_exec,exec,proc_close,proc_open,popen,system,dl,passthru,escapeshellarg,escapeshellcmd
I have CentOS running on my VPS.
	View 13 Replies
    View Related
  
    
	
    	
    	
        Mar 25, 2008
        As with many sites. my site was hacked recently. my host was so negative about this. they didn't notice the hack attempt although it took the hacker 9 hours to break through.
after that I made some search on my host to find that it is not a real host at all. they are just resellers to another company. I was very disappointed, Then I decided to go to a better host who can protect me from hackers.
I read some threads about 'hacker safe host' but they all in general don't give a real name of trusted 'anti-hackers' companies.
can you guide me to some of the famous hosts?
if you can't my friends got a VPS hosted with WestHost. he offered me to move my site to his VPS. is west host trusted about hackers?
	View 14 Replies
    View Related
  
    
	
    	
    	
        Feb 12, 2008
        I am running my VPS on direct admin panel, my disk space is going low, so i am deleting few junk / log files
Kindly let me know
1) is it safe to delete data of this directory -
/var/log/httpd/domains
The File names in above directory are such as - " domain.com.bytes "
As it is occupying 600 MB space
2) where can i delete much junk / temp files, to free up space.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Nov 7, 2007
        I am trying to assist a customer install a Dolphin CMS but it returns some "open_basedir restriction in effect" on /usr/local/bin/php (it needs the path to the PHP binary).
If I put /usr/local/bin/php in httpd.conf -> php_admin_value open_basedir "..." it seems to work and it finds the required binary but...is this safe?
	View 10 Replies
    View Related
  
    
	
    	
    	
        Sep 19, 2007
        I stumbled upon this through google images...click as you wish. They are clothed, just riskay. And in calpop! LOL! I wonder who that guy is? Yes, off topic I know. Maybe a repost.
[url]
	View 14 Replies
    View Related