RE: [PHP-CVS] cvs: php4 / NEWS php.ini-dist php.ini-optimized php.ini-recommended
| From: | MÃ¥rten Gustafsson | Date: | Mon, 13 Aug 2001 21:09:29 +0000 |
| Subject: | RE: [PHP-CVS] cvs: php4 / NEWS php.ini-dist php.ini-optimized php.ini-recommended | ||
| References: | 1 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-6787@lists.php.net to get a copy of this message | ||
Correct me if I´m wrong, I´m talking from an Apache point of view.
A short question about this:
> -; - variables_order = "GPCS"
> +; - variables_order = "GPCS" [Performance]
is "S" really needed? I´ve lived without it for quite some time, since all
those variables can be fetched with getenv().
Marten.
> -----Original Message-----
> From: Zeev Suraski [mailto:zeev@zend.com]
> Sent: Saturday, August 11, 2001 5:23 PM
> To: php-cvs@lists.php.net
> Subject: [PHP-CVS] cvs: php4 / NEWS php.ini-dist php.ini-optimized
> php.ini-recommended
>
>
> zeev Sat Aug 11 11:22:56 2001 EDT
>
> Removed files:
> /php4 php.ini-optimized
>
> Modified files:
> /php4 NEWS php.ini-dist php.ini-recommended
> Log:
> Start pushing register_globals annihilation
>
>
> Index: php4/NEWS
> diff -u php4/NEWS:1.731 php4/NEWS:1.732
> --- php4/NEWS:1.731 Thu Aug 9 20:10:30 2001
> +++ php4/NEWS Sat Aug 11 11:22:56 2001
> @@ -1,8 +1,11 @@
> PHP 4.0
> NEWS
>
> ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
> |||||||||||||
> ?? ??? 200?, Version 4.0.7-dev
> +- Replaced php.ini-optimized with php.ini-recommended. As the
> name implies,
> + it's warmly recommended to use this file as the basis for your PHP
> + configuration, rather than php.ini-dist. (Zeev)
> - Restore xpath_eval() and php_xpathptr_eval() for 4.0.7. There
> - are still some known leaks.
> + are still some known leaks. (Joey)
> - Added import_request_variables(), to allow users to safely import form
> variables to the global scope (Zeev)
> - Introduced a new $_REQUEST array, which includes any GET, POST
> or COOKIE
> Index: php4/php.ini-dist
> diff -u php4/php.ini-dist:1.91 php4/php.ini-dist:1.92
> --- php4/php.ini-dist:1.91 Fri Aug 10 22:53:57 2001
> +++ php4/php.ini-dist Sat Aug 11 11:22:56 2001
> @@ -1,5 +1,15 @@
> [PHP]
> -; $Id: php.ini-dist,v 1.91 2001/08/11 02:53:57 avsm Exp $
> +
> +;;;;;;;;;;;
> +; WARNING ;
> +;;;;;;;;;;;
> +; This is the default settings file for new PHP installations.
> +; By default, PHP installs itself with a configuration suitable for
> +; development purposes, and *NOT* for production purposes.
> +; For several security-oriented considerations that should be taken
> +; before going online with your site, please consult php.ini-recommended
> +; and http://php.net/manual/en/security.php.
> +
>
> ;;;;;;;;;;;;;;;;;;;
> ; About this file ;
> Index: php4/php.ini-recommended
> diff -u php4/php.ini-recommended:1.45 php4/php.ini-recommended:1.46
> --- php4/php.ini-recommended:1.45 Fri Aug 10 22:53:56 2001
> +++ php4/php.ini-recommended Sat Aug 11 11:22:56 2001
> @@ -4,7 +4,11 @@
> ; About this file ;
> ;;;;;;;;;;;;;;;;;;;
> ;
> -; This is the 'optimized', PHP 4-style version of the php.ini-dist file.
> +; This is the recommended, PHP 4-style version of the
> php.ini-dist file. It
> +; sets some non standard settings, that make PHP more efficient
> and more secure.
> +; The price is that with these settings, PHP may be incompatible
> with some
> +; applications. Using this file is warmly recommended for
> production sites.
> +;
> ; For general information about the php.ini file, please consult
> the php.ini-dist
> ; file, included in your PHP distribution.
> ;
> @@ -14,26 +18,44 @@
> ; PHP 3. Please make sure you read what's different, and modify
> your scripts
> ; accordingly, if you decide to use this file instead.
> ;
> -; - allow_call_time_pass_reference = Off
> -; It's not possible to decide to force a variable to be
> passed by reference
> -; when calling a function. The PHP 4 style to do this is by
> making the
> -; function require the relevant argument by reference.
> -; - register_globals = Off
> +; - register_globals = Off [Security, Performance]
> ; Global variables are no longer registered for input data
> (POST, GET, cookies,
> ; environment and other server variables). Instead of using
> $foo, you must use
> -; $HTTP_POST_VARS["foo"], $HTTP_GET_VARS["foo"],
> $HTTP_COOKIE_VARS["foo"],
> -; $HTTP_ENV_VARS["foo"] or $HTTP_SERVER_VARS["foo"],
> depending on which kind
> -; of input source you're expecting 'foo' to come from.
> -; - register_argc_argv = Off
> +; you can use $_REQUEST["foo"] (includes any variable that
> arrives through the
> +; request, namely, POST, GET and cookie variables), or use
> one of the specific
> +; $_GET["foo"], $_POST["foo"], $_COOKIE["foo"] or
> $_FILES["foo"], depending
> +; on where the input originates.
> +; Note that register_globals is going to be depracated
> (i.e., turned off by
> +; default) in the next version of PHP, because it often
> leads to security bugs.
> +; Read http://php.net/manual/en/security.registerglobals.php;sÌ 9€Wì
> f�:©¸
> for further
> +; information.
> +; - display_errors = Off [Security]
> +; With this directive set to off, errors that occur during
> the execution of
> +; scripts will no longer be displayed as a part of the
> script output, and thus,
> +; will no longer be exposed to remote users. With some
> errors, the error message
> +; content may expose information about your script, web
> server, or database
> +; server that may be exploitable for hacking. Production
> sites should have this
> +; directive set to off.
> +; - log_errors = On [Security]
> +; This directive complements the above one. Any errors that
> occur during the
> +; execution of your script will be logged (typically, to
> your server's error log,
> +; but can be configured in several ways). Along with
> setting display_errors to off,
> +; this setup gives you the ability to fully understand what
> may have gone wrong,
> +; without exposing any sensitive information to remote users.
> +; - register_argc_argv = Off [Performance]
> ; Disables registration of the somewhat redundant $argv and
> $argc global
> ; variables.
> -; - magic_quotes_gpc = Off
> +; - magic_quotes_gpc = Off [Performance]
> ; Input data is no longer escaped with slashes so that it
> can be sent into
> ; SQL databases without further manipulation. Instead, you
> should use the
> ; function addslashes() on each input element you wish to
> send to a database.
> -; - variables_order = "GPCS"
> +; - variables_order = "GPCS" [Performance]
> ; The environment variables are not hashed into the
> $HTTP_ENV_VARS[]. To access
> ; environment variables, you can use getenv() instead.
> +; - allow_call_time_pass_reference = Off [Code cleanliness]
> +; It's not possible to decide to force a variable to be
> passed by reference
> +; when calling a function. The PHP 4 style to do this is by
> making the
> +; function require the relevant argument by reference.
>
>
> ;;;;;;;;;;;;;;;;;;;;
> @@ -167,7 +189,7 @@
> ; error_reporting = E_ALL & ~E_NOTICE
> ; show all errors, except for notices
> ; error_reporting = E_COMPILE_ERROR|E_ERROR|E_CORE_ERROR ;
> show only errors
> error_reporting = E_ALL & ~E_NOTICE ;
> Show all errors except for notices
> -display_errors = On ; Print out errors (as a
> part of the output)
> +display_errors = Off ; Print out errors (as a
> part of the output)
> ; For production
> web sites, you're strongly encouraged
> ; to turn this
> feature off, and use error logging instead (see below).
> ; Keeping
> display_errors enabled on a production web site may reveal
> @@ -177,7 +199,7 @@
>
> ; PHP's startup sequence are not displayed. It's strongly
>
> ; recommended to keep display_startup_errors off, except for
>
> ; when debugging.
> -log_errors = Off ; Log errors into a log
> file (server-specific log, stderr, or error_log (below))
> +log_errors = On ; Log errors into a log
> file (server-specific log, stderr, or error_log (below))
> ; As stated above,
> you're strongly advised to use error logging in place of
> ; error displaying
> on production web sites.
> track_errors = Off ; Store the last error/warning
> message in $php_errormsg (boolean)
>
>
>
> --
> PHP CVS Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-cvs-unsubscribe@lists.php.net
> For additional commands, e-mail: php-cvs-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>