Am 07.06.2011 16:59, schrieb Martin Scotta:

> Most admins are not even aware of this, others really don't care -- how many
> host are up to date?
> So why relying on them?

2.6.35.13-92.fc14.x86_64 #1 SMP Sat May 21 17:26:25 UTC 2011
httpd-2.2.19-2.fc14.rh.20110526.x86_64
apr-1.4.5-1.fc14.rh.20110522.x86_64.rpm
mod_security-2.6.0-3.fc14.rh.20110526.x86_64
php-suhosin-0.9.32.1-13.fc14.rh.20110526.x86_64
mysql-server-5.5.13-2.fc14.rh.20110601.x86_64
phpMyAdmin-3.4.2-2.fc14.rh.20110607.noarch.rpm

disable_functions: popen, pclose, exec, passthru, shell_exec, system, proc_open
proc_close, proc_nice, proc_terminate, proc_get_status, pcntl_exec, 
apache_child_terminate
posix_kill, posix_mkfifo, posix_setpgid, posix_setsid, posix_setuid, mail, 
symlink

so please keep in mind that there are users/admins which are really knowing 
what they
do and try not introduce cool features / defaults while bypassing security
with them only for braindead users thinking enable all you can get is funny

a well configured machine has ALL disabled / uninstalled which is not really 
needed

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to