Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default SECURITY QUESTION - advice from a hosted user. Does this make sense?

    Here is something I just received from a hosted member. Does this make sense? If so, would it mess up any installed packages? If not, how do I implement the following? In the php.ini file? Thanks for any response.

    -------------------------------

    It'd be best if the url_fopen in php configuration disabled by default and if some of the users want it they can always use .htaccess method to enable it, instead of enabled by default and users can't change / override the allow_url_fopen flag in php configuration like now, because it may cause some security risk.

    and maybe you could make users to override the expose_php flag too, because i dont really like it to expose that kind of thing to the whole world

    thanks for your attention, and sorry for my bad english language

  2. #2
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default

    More specifically, will setting allow_url_fopen to OFF mess up any installed scripts?

  3. #3
    Member
    Join Date
    Oct 2002
    Posts
    49

    Default

    "More specifically, will setting allow_url_fopen to OFF mess up any installed scripts?"

    It really depends on what scripts you have installed. I do know of several programs using this option and that will not work completely with this off. So you should at least inform your users about it. You can activate it per user if there is need for it.

  4. #4
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default

    Quote Originally Posted by areha
    "More specifically, will setting allow_url_fopen to OFF mess up any installed scripts?"

    It really depends on what scripts you have installed. I do know of several programs using this option and that will not work completely with this off. So you should at least inform your users about it. You can activate it per user if there is need for it.

    Thanks but how do you activate it per user once this is off in the main server php.ini file?

  5. #5
    Member Host4u2's Avatar
    Join Date
    Mar 2002
    Posts
    245

    Default

    For one... Setting allow_url_fopen to OFF WILL mess up Soholaunch upgrade feature. Without allow_url_fopen ON, you will not be able to download the automatic upgrades.

  6. #6
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default

    Quote Originally Posted by Host4u2
    For one... Setting allow_url_fopen to OFF WILL mess up Soholaunch upgrade feature. Without allow_url_fopen ON, you will not be able to download the automatic upgrades.
    Yet one more reason to stay away from Soholaunch.

    Soholaunch is also not compatible for our customers (and our office staffers) that use MacOSX.

Similar Threads & Tags
Similar threads

  1. Kernel Panic error. Can anyone make sense of this?
    By jols in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-16-2009, 07:14 AM
  2. Disk space used for mail doesnt make sense!
    By johnday in forum cPanel and WHM Discussions
    Replies: 13
    Last Post: 12-23-2006, 03:25 PM
  3. How can I make sense of....
    By lamp in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-12-2004, 08:37 AM
  4. The email message doesnt make any sense
    By sexy_guy in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-02-2003, 07:03 PM
  5. An error message that does not make sense. (phpMyAdmin)
    By akhan in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 02-11-2003, 12:50 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube