Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:53154 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 23433 invoked from network); 7 Jun 2011 15:11:16 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 7 Jun 2011 15:11:16 -0000 Authentication-Results: pb1.pair.com header.from=h.reindl@thelounge.net; sender-id=pass Authentication-Results: pb1.pair.com smtp.mail=h.reindl@thelounge.net; spf=pass; sender-id=pass Received-SPF: pass (pb1.pair.com: domain thelounge.net designates 91.118.73.15 as permitted sender) X-PHP-List-Original-Sender: h.reindl@thelounge.net X-Host-Fingerprint: 91.118.73.15 mail.thelounge.net Windows 98 (1) Received: from [91.118.73.15] ([91.118.73.15:41362] helo=mail.thelounge.net) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 13/A1-15404-29F3EED4 for ; Tue, 07 Jun 2011 11:11:15 -0400 Received: from [10.0.0.99] (rh.thelounge.net [10.0.0.99]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by mail.thelounge.net (Postfix) with ESMTPSA id 2360A9A for ; Tue, 7 Jun 2011 17:11:10 +0200 (CEST) Message-ID: <4DEE3F8D.1050201@thelounge.net> Date: Tue, 07 Jun 2011 17:11:09 +0200 Organization: the lounge interactive design User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.17) Gecko/20110428 Fedora/3.1.10-1.fc14 Lightning/1.0b3pre Thunderbird/3.1.10 MIME-Version: 1.0 To: internals@lists.php.net References: <8757232E56758B42B2EE4F9D2CA019C901499F97@US-EX2.zend.net> <97.45.23189.8060DED4@pb1.pair.com> <4DED5F9B.7060101@thelounge.net> <4DEDC9F5.3030403@thelounge.net> <4DEDF049.7050504@gmail.com> <4DEDF216.6070308@thelounge.net> <4DEE1D47.8060209@gmail.com> <4DEE21C2.5060305@thelounge.net> <4DEE2332.3050705@thelounge.net> In-Reply-To: X-Enigmail-Version: 1.1.2 OpenPGP: id=7F780279; url=http://arrakis.thelounge.net/gpg/h.reindl_thelounge.net.pub.txt Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="------------enigAC92253E3BB94DD6D00CB01F" Subject: Re: [PHP-DEV] Bundling "modern" extensions From: h.reindl@thelounge.net (Reindl Harald) --------------enigAC92253E3BB94DD6D00CB01F Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Am 07.06.2011 16:59, schrieb Martin Scotta: > Most admins are not even aware of this, others really don't care -- how= many > host are up to date? > So why relying on them? 2.6.35.13-92.fc14.x86_64 #1 SMP Sat May 21 17:26:25 UTC 2011 httpd-2.2.19-2.fc14.rh.20110526.x86_64 apr-1.4.5-1.fc14.rh.20110522.x86_64.rpm mod_security-2.6.0-3.fc14.rh.20110526.x86_64 php-suhosin-0.9.32.1-13.fc14.rh.20110526.x86_64 mysql-server-5.5.13-2.fc14.rh.20110601.x86_64 phpMyAdmin-3.4.2-2.fc14.rh.20110607.noarch.rpm disable_functions: popen, pclose, exec, passthru, shell_exec, system, pro= c_open proc_close, proc_nice, proc_terminate, proc_get_status, pcntl_exec, apach= e_child_terminate posix_kill, posix_mkfifo, posix_setpgid, posix_setsid, posix_setuid, mail= , symlink so please keep in mind that there are users/admins which are really knowi= ng what they do and try not introduce cool features / defaults while bypassing securit= y with them only for braindead users thinking enable all you can get is fun= ny a well configured machine has ALL disabled / uninstalled which is not rea= lly needed --------------enigAC92253E3BB94DD6D00CB01F Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/ iEYEARECAAYFAk3uP40ACgkQhmBjz394AnlyFgCeIUfP2EQXFwODf6Q6zMv3iEJo 6ccAn3Iga7ZJu9NIb3YAlaAy6FamJc8m =QMgg -----END PGP SIGNATURE----- --------------enigAC92253E3BB94DD6D00CB01F--