cvs: php4 / NEWS php.ini-dist php.ini-optimized php.ini-recommended
| From: | Zeev Suraski | Date: | Sat, 11 Aug 2001 15:22:56 +0000 |
| Subject: | cvs: php4 / NEWS php.ini-dist php.ini-optimized php.ini-recommended | ||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-6737@lists.php.net to get a copy of this message | ||
zeev Sat Aug 11 11:22:56 2001 EDT
Removed files:
/php4 php.ini-optimized
Modified files:
/php4 NEWS php.ini-dist php.ini-recommended
Log:
Start pushing register_globals annihilation
Index: php4/NEWS
diff -u php4/NEWS:1.731 php4/NEWS:1.732
--- php4/NEWS:1.731 Thu Aug 9 20:10:30 2001
+++ php4/NEWS Sat Aug 11 11:22:56 2001
@@ -1,8 +1,11 @@
PHP 4.0 NEWS
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
?? ??? 200?, Version 4.0.7-dev
+- Replaced php.ini-optimized with php.ini-recommended. As the name implies,
+ it's warmly recommended to use this file as the basis for your PHP
+ configuration, rather than php.ini-dist. (Zeev)
- Restore xpath_eval() and php_xpathptr_eval() for 4.0.7. There
- are still some known leaks.
+ are still some known leaks. (Joey)
- Added import_request_variables(), to allow users to safely import form
variables to the global scope (Zeev)
- Introduced a new $_REQUEST array, which includes any GET, POST or COOKIE
Index: php4/php.ini-dist
diff -u php4/php.ini-dist:1.91 php4/php.ini-dist:1.92
--- php4/php.ini-dist:1.91 Fri Aug 10 22:53:57 2001
+++ php4/php.ini-dist Sat Aug 11 11:22:56 2001
@@ -1,5 +1,15 @@
[PHP]
-; $Id: php.ini-dist,v 1.91 2001/08/11 02:53:57 avsm Exp $
+
+;;;;;;;;;;;
+; WARNING ;
+;;;;;;;;;;;
+; This is the default settings file for new PHP installations.
+; By default, PHP installs itself with a configuration suitable for
+; development purposes, and *NOT* for production purposes.
+; For several security-oriented considerations that should be taken
+; before going online with your site, please consult php.ini-recommended
+; and http://php.net/manual/en/security.php.
+
;;;;;;;;;;;;;;;;;;;
; About this file ;
Index: php4/php.ini-recommended
diff -u php4/php.ini-recommended:1.45 php4/php.ini-recommended:1.46
--- php4/php.ini-recommended:1.45 Fri Aug 10 22:53:56 2001
+++ php4/php.ini-recommended Sat Aug 11 11:22:56 2001
@@ -4,7 +4,11 @@
; About this file ;
;;;;;;;;;;;;;;;;;;;
;
-; This is the 'optimized', PHP 4-style version of the php.ini-dist file.
+; This is the recommended, PHP 4-style version of the php.ini-dist file. It
+; sets some non standard settings, that make PHP more efficient and more secure.
+; The price is that with these settings, PHP may be incompatible with some
+; applications. Using this file is warmly recommended for production sites.
+;
; For general information about the php.ini file, please consult the php.ini-dist
; file, included in your PHP distribution.
;
@@ -14,26 +18,44 @@
; PHP 3. Please make sure you read what's different, and modify your scripts
; accordingly, if you decide to use this file instead.
;
-; - allow_call_time_pass_reference = Off
-; It's not possible to decide to force a variable to be passed by reference
-; when calling a function. The PHP 4 style to do this is by making the
-; function require the relevant argument by reference.
-; - register_globals = Off
+; - register_globals = Off [Security, Performance]
; Global variables are no longer registered for input data (POST, GET, cookies,
; environment and other server variables). Instead of using $foo, you must use
-; $HTTP_POST_VARS["foo"], $HTTP_GET_VARS["foo"],
$HTTP_COOKIE_VARS["foo"],
-; $HTTP_ENV_VARS["foo"] or $HTTP_SERVER_VARS["foo"], depending on which
kind
-; of input source you're expecting 'foo' to come from.
-; - register_argc_argv = Off
+; you can use $_REQUEST["foo"] (includes any variable that arrives through the
+; request, namely, POST, GET and cookie variables), or use one of the specific
+; $_GET["foo"], $_POST["foo"], $_COOKIE["foo"] or
$_FILES["foo"], depending
+; on where the input originates.
+; Note that register_globals is going to be depracated (i.e., turned off by
+; default) in the next version of PHP, because it often leads to security bugs.
+; Read http://php.net/manual/en/security.registerglobals.php
for further
+; information.
+; - display_errors = Off [Security]
+; With this directive set to off, errors that occur during the execution of
+; scripts will no longer be displayed as a part of the script output, and thus,
+; will no longer be exposed to remote users. With some errors, the error message
+; content may expose information about your script, web server, or database
+; server that may be exploitable for hacking. Production sites should have this
+; directive set to off.
+; - log_errors = On [Security]
+; This directive complements the above one. Any errors that occur during the
+; execution of your script will be logged (typically, to your server's error log,
+; but can be configured in several ways). Along with setting display_errors to off,
+; this setup gives you the ability to fully understand what may have gone wrong,
+; without exposing any sensitive information to remote users.
+; - register_argc_argv = Off [Performance]
; Disables registration of the somewhat redundant $argv and $argc global
; variables.
-; - magic_quotes_gpc = Off
+; - magic_quotes_gpc = Off [Performance]
; Input data is no longer escaped with slashes so that it can be sent into
; SQL databases without further manipulation. Instead, you should use the
; function addslashes() on each input element you wish to send to a database.
-; - variables_order = "GPCS"
+; - variables_order = "GPCS" [Performance]
; The environment variables are not hashed into the $HTTP_ENV_VARS[]. To access
; environment variables, you can use getenv() instead.
+; - allow_call_time_pass_reference = Off [Code cleanliness]
+; It's not possible to decide to force a variable to be passed by reference
+; when calling a function. The PHP 4 style to do this is by making the
+; function require the relevant argument by reference.
;;;;;;;;;;;;;;;;;;;;
@@ -167,7 +189,7 @@
; error_reporting = E_ALL & ~E_NOTICE ; show all errors, except for notices
; error_reporting = E_COMPILE_ERROR|E_ERROR|E_CORE_ERROR ; show only errors
error_reporting = E_ALL & ~E_NOTICE ; Show all errors except for notices
-display_errors = On ; Print out errors (as a part of the output)
+display_errors = Off ; Print out errors (as a part of the output)
; For production web sites, you're strongly encouraged
; to turn this feature off, and use error logging instead (see below).
; Keeping display_errors enabled on a production web site may reveal
@@ -177,7 +199,7 @@
; PHP's startup sequence are not displayed. It's strongly
; recommended to keep display_startup_errors off, except for
; when debugging.
-log_errors = Off ; Log errors into a log file (server-specific log, stderr, or error_log (below))
+log_errors = On ; Log errors into a log file (server-specific log, stderr, or error_log (below))
; As stated above, you're strongly advised to use error logging in place of
; error displaying on production web sites.
track_errors = Off ; Store the last error/warning message in $php_errormsg (boolean)