Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    A_1
    A_1 is offline
    Member
    Join Date
    Jan 2007
    Posts
    35

    Default I want Make my Server Can't Accept any shell file

    Hello,

    i want make my server can't read any shell file on sites , so when any one want upload any shell file , so that can't read or do any thing
    can any one tell me how i can make that ?

    for info: i have disabled this functions:
    PHP Code:
    curl_initdlexecshell_execsystempassthrupopenpcloseproc_openproc_niceproc_terminateproc_get_statusproc_closepfsockopenleakapache_child_terminateposix_killposix_mkfifoposix_setpgidposix_setsidposix_setuidescapeshellcmdescapeshellarghell-execfpassthruexeccrack_checkcrack_closedictcrack_getlastmessagecrack_opendictpsockopenphp_ini_scanned_filesphp_unamephpinfocopy 
    AND i have already setup mode_security
    and make safe_mode On


    the last what ASK;
    how can disable this open bae dir



    i hope any one can help me

    thanks,

  2. #2
    Member
    Join Date
    Jul 2005
    Location
    Sticky On Internet
    Posts
    555

    Lightbulb

    hi,
    you can set open base dir restriction from WHM-->Tweak security-->Php open_basedir TweaK.

    see ya,
    mohit
    Learn atleast A word Daily

    7+1 Dedicated Boxes with cPanel...

  3. #3
    A_1
    A_1 is offline
    Member
    Join Date
    Jan 2007
    Posts
    35

    Default

    Quote Originally Posted by mohit View Post
    hi,
    you can set open base dir restriction from WHM-->Tweak security-->Php open_basedir TweaK.

    see ya,
    mohit
    thanks , for ur reply
    and what about that first ask ?

  4. #4
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    In reality, what you're asking for simply isn't possible. You can go some way by disabling PHP functions as you've mentioned, but there are ways around that that you cannot avoid without completely breaking PHP. Once you've done all that work, it's still trivial to do in perl which you cannot restrict in that way. It's simply something you have to accept in a shared hosting environment and make sure your server and scripts are as secure as they can be. One essential with PHP is to run with phpsuexec (or suphp) otherwise PHP scripts can access anything in other users sites.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  5. #5
    A_1
    A_1 is offline
    Member
    Join Date
    Jan 2007
    Posts
    35

    Default

    Quote Originally Posted by chirpy View Post
    In reality, what you're asking for simply isn't possible. You can go some way by disabling PHP functions as you've mentioned, but there are ways around that that you cannot avoid without completely breaking PHP. Once you've done all that work, it's still trivial to do in perl which you cannot restrict in that way. It's simply something you have to accept in a shared hosting environment and make sure your server and scripts are as secure as they can be. One essential with PHP is to run with phpsuexec (or suphp) otherwise PHP scripts can access anything in other users sites.
    Thank you for ur answer , and i want ur advice ,
    what function u advice me disable it ? and any secure in PHP


    Thanks

  6. #6
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by A_1 View Post
    i have disabled this functions:
    PHP Code:
    curl_initdlexecshell_execsystempassthrupopenpcloseproc_openproc_niceproc_terminateproc_get_statusproc_closepfsockopenleakapache_child_terminateposix_killposix_mkfifoposix_setpgidposix_setsidposix_setuidescapeshellcmdescapeshellarghell-execfpassthruexeccrack_checkcrack_closedictcrack_getlastmessagecrack_opendictpsockopenphp_ini_scanned_filesphp_unamephpinfocopy 
    This pretty much covers the vast majority of Php functions you can disable in php.ini. Install Mod Security with a very good set of rules.

    Regadring passwords, when choosing a new password, make sure it's unrelated to any previous password. You might use a word pair with punctuation inserted, a pass phrase
    (an understandable sequence of words), or the first letter of each word in a
    pass phrase. In addition, a password must be at least eight characters in length. Just a thought
    Andy Reed
    RHCE and CCNA
    ServerTune.com

  7. #7
    A_1
    A_1 is offline
    Member
    Join Date
    Jan 2007
    Posts
    35

    Default

    Quote Originally Posted by AndyReed View Post
    This pretty much covers the vast majority of Php functions you can disable in php.ini. Install Mod Security with a very good set of rules.

    Regadring passwords, when choosing a new password, make sure it's unrelated to any previous password. You might use a word pair with punctuation inserted, a pass phrase
    (an understandable sequence of words), or the first letter of each word in a
    pass phrase. In addition, a password must be at least eight characters in length. Just a thought
    many thanks bro for ur reply

    u have any good mode_secuirty ?
    and how install it ?

    thanks,

Similar Threads & Tags
Similar threads

  1. Server won't accept more than 128 connections... (tried everything)
    By Drowned in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 06-13-2009, 04:30 AM
  2. Replies: 5
    Last Post: 01-16-2008, 01:05 PM
  3. What changes can I make to sysctl.conf to make the server perform better?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-11-2005, 11:25 AM
  4. Can I make databases made from shell display in cPanel?
    By kovacs in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 03-30-2005, 05:37 PM
  5. Replies: 6
    Last Post: 06-23-2004, 10:36 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube