Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Jan 2006
    Location
    Mulund, India, India
    Posts
    118

    Default Ideal PHP settings for Cpanel/WHM

    Hello All,

    Can anybody tell me what are the ideal settings of PHP for cpanel/WHM. Many of the customers ask for certain settings to be done in PHP so that their applications work fine. I want to know which modules/variables should be enabled and which should be disabled so that there is no problem with the server security and also maximum applications work fine. I also have Fantastico enabled.
    Nitesh Shah

    Cheap Managed Dedicated Servers - http://www.qualispace.com/managed-servers/index.html

  2. #2
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    10,720
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by nitaish View Post
    Hello All,

    Can anybody tell me what are the ideal settings of PHP for cpanel/WHM. Many of the customers ask for certain settings to be done in PHP so that their applications work fine. I want to know which modules/variables should be enabled and which should be disabled so that there is no problem with the server security and also maximum applications work fine. I also have Fantastico enabled.
    The PHP Hardening Guide in the EA3 documentation is a good starting point: http://www.cpanel.net/support/docs/e...ening_php.html

    We have several server security presentations at this year's cPanel Conference if you wish to learn more about the topic as a whole: http://conference.cPanel.net

    I'm sure this thread will spark some discussion.

    I believe there are 3 things that most would agree should be done for a good PHP setup on a new server: run PHP 5 as SuPHP and turn off register_globals in php.ini. Any scripts that require register_globals or require PHP 4 are likely poorly maintained and likely to have many known vulnerabilities.

    SuPHP will substantially reduce the likelihood of a single exploited account bringing down the entire server. Additionally, with SuPHP, all scripts run as the user so you no longer have to worry about ownership issues and abusive scripts can be tracked to the account running them.

    However, as the documentation states, PHP security is a balancing act between functionality and security and it is best to understand the options you are enabling/disabling when creating your own PHP security procedures.

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Apr 2008
    Location
    PK
    Posts
    443

    Default how to turn register_globals on for one account

    Then how do you suggest, we turn register_globals on for one account...if its server wide disabled

  4. #4
    Member
    Join Date
    May 2003
    Location
    Las Vegas, NV
    Posts
    18

    Default

    You can override the register_globals settings for a single account if necessary by using .htaccess rules or putting a php.ini file in the user's public_html directory (or whatever directory you want those settings changed for).
    Rob Tyree
    Versaweb Hosting Solutions
    Reseller Hosting | VPS Servers | Dedicated Servers | Colocation

Similar Threads & Tags
Similar threads

  1. Ideal days of the week for the next cPanel Conference 2010
    By mario-cPanel in forum cPanel Announcements
    Replies: 3
    Last Post: 03-08-2010, 03:27 AM
  2. What are Ideal backup and log generation settings?
    By maever in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-16-2007, 08:57 AM
  3. New CPanel ideal, what you do think?
    By nick_phost in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 03-21-2007, 03:02 AM
  4. php mail() and whm nobody tewak settings
    By Radio_Head in forum cPanel and WHM Discussions
    Replies: 43
    Last Post: 10-12-2004, 09:33 AM
  5. PHP Ini settings in WHM
    By Getox in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-14-2004, 03:31 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube