Closed Thread
Results 1 to 9 of 9

Thread: Why So Many Functions Disabled For Security???

  1. #1
    TheJeffsta's Avatar
    TheJeffsta is offline x10 Lieutenant TheJeffsta is an unknown quantity at this point
    Join Date
    Sep 2005
    Location
    New Zealand
    Posts
    492

    Why So Many Functions Disabled For Security???

    OMG, I have installed MediaWiki, with a lot of code editing in the install script to get past some security disabled php functions.

    Now that I am using the wiki, I keep getting this popen() disabled warning, this isnt all the time but some of the time, dont know what causes it, but its $@*&@ annoying!

    What is soo bad about dl() and popen()?
    TheJeffsta (Jeffrey N)

    "No matter how much you try, the end result will always end up the way you DO NOT want it!"

  2. #2
    HyperCyber is offline x10Hosting Member HyperCyber is an unknown quantity at this point
    Join Date
    Aug 2007
    Posts
    29

    Re: Why So Many Functions Disabled For Security???

    phpinfo() is desabled too lol

  3. #3
    Brandon's Avatar
    Brandon is offline Former Senior Account Rep Brandon is on a distinguished road
    Join Date
    Jun 2006
    Location
    Tewksbury, MA
    Posts
    9,589

    Re: Why So Many Functions Disabled For Security???

    dl() - Loads the PHP extension given by the parameter library.
    popen() - Opens a pipe to a process executed by forking the command given by command.

    You can see why they are disabled.
    Thanks,
    Brandon Long

  4. #4
    TheJeffsta's Avatar
    TheJeffsta is offline x10 Lieutenant TheJeffsta is an unknown quantity at this point
    Join Date
    Sep 2005
    Location
    New Zealand
    Posts
    492

    Re: Why So Many Functions Disabled For Security???

    Well then why do such innocent scripts use them :@, stupid php coders using disabled functions!

    phpinfo() isnt a security risk :S
    TheJeffsta (Jeffrey N)

    "No matter how much you try, the end result will always end up the way you DO NOT want it!"

  5. #5
    Brandon's Avatar
    Brandon is offline Former Senior Account Rep Brandon is on a distinguished road
    Join Date
    Jun 2006
    Location
    Tewksbury, MA
    Posts
    9,589

    Re: Why So Many Functions Disabled For Security???

    phpinfo() is a security risk, as it reveals any extensions, kernel version, etc installed on our server. Sometimes this can be put in the wrong hands.
    Last edited by Brandon; 09-04-2007 at 04:44 PM.
    Thanks,
    Brandon Long

  6. #6
    TheJeffsta's Avatar
    TheJeffsta is offline x10 Lieutenant TheJeffsta is an unknown quantity at this point
    Join Date
    Sep 2005
    Location
    New Zealand
    Posts
    492

    Re: Why So Many Functions Disabled For Security???

    Stupid 'wrong hands' messing everything up for everyone else
    TheJeffsta (Jeffrey N)

    "No matter how much you try, the end result will always end up the way you DO NOT want it!"

  7. #7
    Corey's Avatar
    Corey is offline VPS Migration Professional Corey is a glorious beacon of lightCorey is a glorious beacon of light
    Join Date
    Dec 2004
    Location
    Northfield, NH
    Posts
    17,151

    Re: Why So Many Functions Disabled For Security???

    Yes, DL is an extremely unsafe function allowing people to dynamically load whatever PHP modules they like.

    We are working on 3 different types of PHP that can be changed for users upon request. Each version of PHP would allow the use of certain restricted functions for people we 'trust' with it. I wanted to roll that out this week but with all the problems and new users I haven't had much time to do anything but answer support requests and deal with server issues.

    Hopefully we'll be able to do this soon.

    -Corey

  8. #8
    TheJeffsta's Avatar
    TheJeffsta is offline x10 Lieutenant TheJeffsta is an unknown quantity at this point
    Join Date
    Sep 2005
    Location
    New Zealand
    Posts
    492

    Re: Why So Many Functions Disabled For Security???

    Thank you Corey!
    TheJeffsta (Jeffrey N)

    "No matter how much you try, the end result will always end up the way you DO NOT want it!"

  9. #9
    Brandon's Avatar
    Brandon is offline Former Senior Account Rep Brandon is on a distinguished road
    Join Date
    Jun 2006
    Location
    Tewksbury, MA
    Posts
    9,589

    Re: Why So Many Functions Disabled For Security???

    This thread seems to be solved, I have locked it, if you have any additional questions, please reopen it or start a new topic.
    Thanks,
    Brandon Long

Closed Thread

Similar Threads

  1. posix_getpwuid() disabled for security reasons
    By epichero in forum Free Hosting
    Replies: 1
    Last Post: 08-16-2007, 05:59 PM
  2. Replies: 7
    Last Post: 08-06-2007, 09:31 AM
  3. Torch's PHP Functions Library
    By Torch in forum Scripts & 3rd Party Apps
    Replies: 2
    Last Post: 01-04-2007, 03:11 PM
  4. Fantastico Disabled?
    By Bonekhan in forum Free Hosting
    Replies: 4
    Last Post: 10-25-2006, 10:31 PM
  5. WGET Disabled \ Shell access NOT allowed
    By Corey in forum News and Announcements
    Replies: 8
    Last Post: 10-06-2006, 06:10 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
x10hosting free hosting for the masses
dedicated servers