4 ms·
Which is why I suggested Suhoshin above: https://news.ycombinator.com/item?id=8056907 https://news.ycombinator.com/item?id=8056907 And on a number of replies ad
by ejr 12y ago
Which is why I suggested Suhoshin above: https://news.ycombinator.com/item?id=8056907 https://news.ycombinator.com/item?id=8056907 And on a number of replies advocated for certain precautions in addition to the much maligned disable_functions list.
I'm not going to visit this thread any longer as it's getting to be an exhausting exercise of having to wade through snark and general malaise. I'm reminded, once again, why I waited so long before making a single post on this forum.
- oldmanjay 12y agoYou might want to look into lightening up a little. You gave objectively bad advice, backed by objectively bad reasoning, and were educated about your mistakes for free. There was a bit of snark, but not a single drop of general malaise, and most of what was said to you was very helpful considering your professed aims. You found yourself in "Wovon man nicht sprechen kann, darüber muß man schweigen" territory on this topic, but don't be disheartened. Proper security is notably difficult.
- scintill76 12y agoWhich specifically of my points will be addressed by adding Suhosin? You gave some good advice. Assuming your software still works without cURL and with Suhosin, yes, you are probably going to avoid some attacks by using your disable_functions list and Suhosin. Still, I think what I and several others take issue with, is giving an example php.ini that was so incomplete and inconsistent with its reasoning.