On 10/13/2014 04:54 PM, Ben Johnson wrote: > If there is a better way to deal with this nuisance than resorting to > stricter authentication protocols, I would love to hear alternate > suggestions. [php direct mailing]
Have you considered adding "system" to the list of disallowed function calls? (I remember someone else mentioning this.) http://www.cyberciti.biz/faq/linux-unix-apache-lighttpd-phpini-disable-functions/