Differences
This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revision Both sides next revision | ||
php [2007/02/13 01:16] a |
php [2009/01/05 19:17] a Suhosin Configuration |
||
---|---|---|---|
Line 1: | Line 1: | ||
====== PHP tips ====== | ====== PHP tips ====== | ||
===== Instalation tips ===== | ===== Instalation tips ===== | ||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
Line 13: | Line 19: | ||
display_errors = Off \\ | display_errors = Off \\ | ||
allow_url_fopen = Off \\ | allow_url_fopen = Off \\ | ||
+ | |||
+ | session.use_trans_sid = 0 \\ | ||
+ | session.use_only_cookies = 1 \\ | ||
# | # | ||
Line 19: | Line 28: | ||
php_admin_flag safe_mode On | php_admin_flag safe_mode On | ||
php_admin_value open_basedir "/ | php_admin_value open_basedir "/ | ||
+ | php_admin_value sendmail_from webmaster@example.com | ||
+ | |||
+ | |||
+ | php_admin_flag display_errors On | ||
+ | php_admin_value safe_mode_include_dir "/ | ||
+ | # | ||
+ | php_admin_value default_charset " | ||
+ | |||
+ | |||
FIXME - styling needed | FIXME - styling needed | ||
- | '' | + | **PHP to secure a setup, a good start is a secure php.ini, for example:** |
- | PHP to secure a setup, a good start is a secure php.ini, for example: | + | * disable the Fopen Wrapper, allow_url_fopen = Off |
- | - disable the Fopen Wrapper, allow_url_fopen = Off | + | * use disable_classes and disable_functions like |
- | - use disable_classes and disable_functions like ini_alter, ini_get_all, | + | ini_alter, ini_get_all, |
- | - set register_globals = off | + | |
- | - set log_errors = on, error_reporting and error_log | + | |
- | - use open_basedir and include_path | + | * set log_errors = on, error_reporting and error_log |
- | - use safe_mode if possible'' | + | * use open_basedir and include_path |
+ | * use safe_mode if possible | ||
=== see also: === | === see also: === | ||
+ | * **[[http:// | ||
* [[http:// | * [[http:// | ||
* [[http:// | * [[http:// | ||
+ | * [[http:// | ||