I'd say making a php.ini option, which would allow admin to set this value is a good idea. Althought I would recommend making it an option ONLY changeable via php.ini or httpd.conf (for Apache users). So that by placing a 100 byte php script a user on the server would not be able to cause a DOS.
Much shorter script does the same.
User may write
<?php sleep(999999999)?>
so we don't have to worry about abuse of
configurable longer timeout and it should be
changable from script.
BTW, if users really want to protect server
against simple DoS, they should limit number
of SYN packets using firewall.
--
Yasuo Ohgaki