PHP Developers Network

A community of PHP developers offering assistance, advice, discussion, and friendship.
 
Loading
It is currently Thu Jul 09, 2020 9:36 pm

All times are UTC - 5 hours




Post new topic Reply to topic  [ 3 posts ] 
Author Message
 Post subject: disable_fucntions
PostPosted: Tue Apr 05, 2005 12:54 am 
Offline
Forum Newbie

Joined: Sat Apr 10, 2004 11:17 pm
Posts: 18
Probally getting sick of me by now, eh? :P

I've added the following line in php.ini:
disable_functions = exec,shell_exec,dir,readfile,dl,passthru,popen,chown,phpinfo,chown,system

I do this because

A) Permission setup. All users are part of the group users. All folders/files in /home are 705

B) PHP runs as an 'other' (if it didn't no user could use php scripts)

C) since PHP can read users scripts, other users can abuse the above commands to view (and possibly change!) a users files. Bad stuff.

What I would like to do is this:
Keep those functions disabled, but allow the php files in a certain directory (mainly my htdocs directory, not writable by anyone by root and nobody) to use the diabled functions.

Is there a way to do this?


Top
 Profile  
 
 Post subject:
PostPosted: Tue Apr 05, 2005 1:00 am 
Offline
Neighborhood Spidermoddy
User avatar

Joined: Mon Mar 29, 2004 4:24 pm
Posts: 31559
Location: Bothell, Washington, USA
notice:[code=""]disable_functions &quote;&quote; php.ini only


Top
 Profile  
 
 Post subject:
PostPosted: Tue Apr 05, 2005 2:33 am 
Offline
Forum Newbie

Joined: Sat Apr 10, 2004 11:17 pm
Posts: 18


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 12 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group