Membership
Main Menu
Forum Boards
Stats
- 20 tutorials
- 74,815 members
- 734,914 forum posts
- 13 blog posts
Tutorials
Hardening PHP with Suhosin
by Thomas Johnson on May 27, 2008 2:14:27 PM
Views: 7700
Configuration
The basic configuration that ships with suhosin will work out-of-the-box but I have added a few tweaks.
In the suhosin.ini we add the following:
Enable suhosin
extension=suhosin.so
Disable session encryption (required for most login scripts)
suhosin.session.encrypt = Off
Log all errors
suhosin.log.syslog=511
Max traversal depth ie '../../'
suhosin.executor.include.max_traversal=4
Disable eval
suhosin.executor.disable_eval=On
Disable /e modifier
suhosin.executor.disable_emodifier=On
Disallow newlines in Subject:, To: headers and double newlines in additional headers
suhosin.mail.protect=2
Recommend Settings
Silently fail all failed sql queries
suhosin.sql.bailout_on_error=On
That is it. That was easy, right? For more configuration options see the Suhosin Configuration Documentation.
- « Previous
- 1
- 2
- 3
- 4
Comments
1. Corbin H on May 28, 2008 4:49:03 AM
2. Thomas Johnson on May 28, 2008 8:50:44 AM
3. Corbin H on May 28, 2008 11:35:55 AM
4. Thomas Johnson on May 28, 2008 12:18:51 PM
5. Corbin H on May 28, 2008 3:34:49 PM
6. gizmola on May 29, 2008 12:57:20 PM
7. Corbin H on May 30, 2008 3:22:30 AM
Login or register to post a comment.
