Req #50802 [Com]: Allow "disable_functions" in httpd.conf

From: Date: Thu, 16 Mar 2017 01:34:18 +0000
Subject: Req #50802 [Com]: Allow "disable_functions" in httpd.conf
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207862@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=50802&edit=1 ID: 50802 Comment by: own3mall at gmail dot com Reported by: h dot reindl at thelounge dot net Summary: Allow "disable_functions" in httpd.conf Status: Wont fix Type: Feature/Change Request Package: Feature/Change Request Operating System: All PHP Version: 5.2.12 Block user comment: N Private report: N New Comment: In nginx, with fastcgi you can override the setting in the template: fastcgi_param PHP_ADMIN_VALUE "disable_functions=exec,passthru,shell_exec,system,proc_open,popen"; And, it WORKS there. OK, so why can't we do this with php in Apache2? Surely, the performance wouldn't be that much of a hit. I don't want to disable the above functions globally since some of my sites absolutely need some of those functions, but shared hosting users shouldn't be able to run them. I also don't want to use Suhosin, period. Surely this can be fixed to work on Apache2 as it does with nginx and php-fpm? Previous Comments: ------------------------------------------------------------------------ [2013-06-30 20:14:44] spamik at yum dot pl disable_functions should be made PHP_INI_ALL with exception that once set in can't be set to less restrictive (like open_basedir is nowadays). Yes it is tought to make because of curent code, but that is no reason to reject feature request completly! Don't reject it, maybe some dev someday will find motivation to do this. ------------------------------------------------------------------------ [2012-01-30 02:23:04] k dot reznichak at pcpin dot com Hello, any updates here? Doesn't matter if "suhosin"-like or any other way, this feature would dramatically simplify server administration and reduce costs. My current solution with different apache instances listening on different ports via proxy was pain to set up and hurts every time I manage it. Please consider that some admins just going easy way by enabling sensitive functions globally for all virtual hosts causing security risk. That does not means PHP is insecure by itself, however it encourages people to act insecure. Kind Regards ------------------------------------------------------------------------ [2010-01-29 15:45:08] h dot reindl at thelounge dot net > Suhosin doesn't disable functions. > It adds a separate blacklist > mechanism. Yes, and it works fine > This bug was about being able to do per-request disabling > with the existing disable_function mechanism. And shows that the existing mechnism is poorly implemented if you need a extension to make a SECURITY-SETTING usable which is able to do nearly the same and would not be needed if the php-core does handle this better ------------------------------------------------------------------------ [2010-01-29 15:39:30] rasmus@php.net Suhosin doesn't disable functions. It adds a separate blacklist mechanism. This bug was about being able to do per-request disabling with the existing disable_function mechanism. ------------------------------------------------------------------------ [2010-01-29 14:43:51] h dot reindl at thelounge dot net http://www.webhostingtalk.com/showthread.php?t=623944 If it is not possible because performance why it works with suhosin-extension perfectly with the only problem that "function_exists()" does not realize the suhosin setting? Sorry, but this sounds like "it's possible but i say is not because i do not like to touch the code" ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=50802 -- Edit this bug report at https://bugs.php.net/bug.php?id=50802&edit=1

« previous php.bugs (#207862) next »