This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Core bug on the mail creation with PHP 7.2
#6
RE: Core bug on the mail creation with PHP 7.2
(08-22-2018, 06:41 AM)TGates Wrote: After a quick read through, Snuffleupagus looks to be promising if Suhosin doesn't come around. I didn't get to check on all of the functions it blocks, but that shouldn't be too hard to sort out.

The list of functions looks to be extensive, including an out-of-the-box config (or "rule") file that doesn't allow Sentora Panel to run without some tweaking...

...and you might ask why I have it running for the panel when Suhosin was only configured to be loaded up for vhost user sites and not the main Sentora panel... or at least that what I think happens with Suhosin but correct me if I'm wrong. The main problem I have found with Snuffleupagus is that if it is configured to run for vhosts, and I open a page of one of my vhosts, the panel then won't run for 30 secs or so. In short, Snuffleupagus is bound into PHP and if the vhosts are set to run with a valid rules file but Sentora doesn't, the vhost rules seem to still run when loading the Sentora panel. My compromise has been to run PHP with a rules file defined regardless of whether it's Sentora or one of the other vhosts on the server, but without the default rules for theĀ "include-related vulnerabilities" as those seem to break Sentora and I don't think Suhosin ever blocked using any of the "include" functions.

Could be tricky to get it working in the same way Suhosin does but so far it's the only thing that sells itself as a PHP 7 replacement for Suhosin that I can find. Certainly worth playing around with...

Keith.
Reply
Thanks given by:


Messages In This Thread
RE: Core bug on the mail creation with PHP 7.2 - by fearworks - 08-22-2018, 08:51 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)