|
|
|
|
![]() ![]() |
Nov 26 2006, 05:00 PM
Post
#1
|
|
|
A clever man learns from his own mistakes, a WISE man learns from those of OTHERS ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: [HOSTED] Posts: 1,028 Joined: 12-April 06 From: Essex, UK Member No.: 21,719 |
Hi everyone, it suddenly hit me that i might be vulnerable to remote include attacks on my website via the allow_fopen_url in the php.ini config file.
What i want to know is if its possible for me to edit the php.ini file to turn off this value ( i notice it is on for me from the phpinfo page in the cpanel ) or if this isnt possible any way that i can modify my scripts if needed (if this is the case ill ask for this post to be locked and ill repost this question in the php programming section) Thanks. |
|
|
|
Nov 26 2006, 06:45 PM
Post
#2
|
|
|
Super Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 357 Joined: 8-April 06 Member No.: 21,487 |
Dear shadowx i think You dont have access to php.ini file and you can zend your soruce for more security or make webprotect for this file and hotlink ( in cpanel )
|
|
|
|
Nov 26 2006, 07:13 PM
Post
#3
|
|
|
A clever man learns from his own mistakes, a WISE man learns from those of OTHERS ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: [HOSTED] Posts: 1,028 Joined: 12-April 06 From: Essex, UK Member No.: 21,719 |
mm i couldn't find it. i know i can use all sorts of data filtering in my php but thats effort!! i was hoping for a simpler alternative in the ini file
|
|
|
|
Nov 27 2006, 12:54 AM
Post
#4
|
|
|
A computer once beat me at chess, but it was no match for me at kick boxing. ![]() Group: [MODERATOR] Posts: 4,081 Joined: 24-July 05 From: Linix, DOS and Windows…the good, the bad and the ugly Member No.: 9,787 ![]() |
It appears that directive can only be set via the php.ini file settings.
http://us3.php.net/manual/en/ref.filesyste...allow-url-fopen |
|
|
|
![]() ![]() |
Similar Topics
| Topics | Topics | |
|---|---|---|
|
|
|
|
Lo-Fi Version | Time is now: 12th October 2008 - 03:29 PM |