Previous Thread
Next Thread
Print Thread
Rate Thread
#210981 07/23/2001 8:28 PM
Joined: Jul 2001
Posts: 442
Enthusiast
Enthusiast
Offline
Joined: Jul 2001
Posts: 442
Just received this from my host, is this something I have to worry about? I am running PHP 5.4.2

Our PHP team has done more research and revised our plans to improve security on our systems as it relates to PHP. These changes will be rolling out in steps over the next two weeks. The first change will go into effect next Wed, July 25th.

This announcement is here to outline exactly which changes will be put into effect so you can take appropriate action to ensure your site will not be harmed. If you are unsure how to modify your PHP or if you need to modify your PHP at all, please contact our support team for assistance.


PHP Security Changes:

1. The use of the backtick operator (``) will be disabled. Any PHP using that operator must be changed.

2. The following PHP functions will be disabled:
exec, system, passthru, popen, chmod, is_file
Any PHP using any of those functions must be changed.

3. php's open_basedir configuration option will be set for each of your sites, limiting you to only be able to open, read, write, or include files from the home directory corresponding to your site or any directory underneath that directory. You will not be able to open a file from another home directory (even if it is one of your own users). This last change may be the most significant and there is a work-around allowing your site to access files in multiple home directories. Please contact us if you need that special configuration set up for you and we will do so.


This announcement is intended as an advance warning for these upcoming changes. Please take the proper considerations to ensure your site experiences no down time. If you have any questions about this at all, please contact our support team.


Thanks guys
Steve




Sponsored Links
bisbell #210982 07/24/2001 8:17 AM
Joined: May 1999
Posts: 3,039
Guru
Guru
Offline
Joined: May 1999
Posts: 3,039
No worries for this program. None of the mentioned functions or methods are used.


UBB.threads Developer
Sally #210983 07/24/2001 11:13 AM
Joined: Jul 2001
Posts: 442
Enthusiast
Enthusiast
Offline
Joined: Jul 2001
Posts: 442
Cool beans


bisbell #210984 07/25/2001 1:54 AM
Joined: Apr 2001
Posts: 11
Power User
Power User
Offline
Joined: Apr 2001
Posts: 11
Can anyone explain why is_file( ) is a security risk, just in case I consider using it in one of my w3t hacks.


--<br>Roger

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Shock Hosting
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Zarzal
Zarzal
Berlin, Germany
Posts: 808
Joined: July 2001
Forum Statistics
Forums63
Topics37,583
Posts293,955
Members13,825
Most Online151,614
Nov 14th, 2025
Today's Statistics
Currently Online 2595
Topics Created 0
Posts Made 0
Users Online 0
Birthdays 5
Top Posters
AllenAyres 21,080
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,834
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2026 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.1.0
(Snapshot build 20260108)