vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Forum and Server Management (https://vborg.vbsupport.ru/forumdisplay.php?f=232)
-   -   Suhosin (https://vborg.vbsupport.ru/showthread.php?t=175249)

Jase2 04-05-2008 06:24 PM

Suhosin
 
Hi all,

I ran a diagnostics, and it says: Suhosin Module Loaded Yes.

Quote:

Suhosin can limit the amount of data submitted and encrypt cookies causing problems with several aspects of vBulletin.
Anyone know how to disable this?

snakes1100 04-05-2008 07:12 PM

Unless you can modify php.ini you cant, unless your host allows php.ini over riding per host, ask your host.

Jase2 04-05-2008 07:21 PM

Definitely causing issues.

I'll try increasing:

* php_value suhosin.post.max_vars
* php_value suhosin.request.max_vars

Opserty 04-05-2008 07:35 PM

Search vBulletin.com I remember a post there a while back defining the settings required.

Jase2 04-05-2008 07:45 PM

<a href="http://www.vbulletin.com/forum/showthread.php?p=1329782#post1329782" target="_blank">http://www.vbulletin.com/forum/showt...82#post1329782</a>

Marco van Herwaarden 04-06-2008 10:22 AM

Moved to Server Management.

TECK 04-13-2008 06:50 AM

Take off Suhosin, it is designed to slowdown your server.
Why do you need a hardened PHP version? Just define a good set of rules in Selinux.

wolfstream 04-22-2008 01:44 PM

Quote:

Originally Posted by TECK (Post 1489564)
Take off Suhosin, it is designed to slowdown your server.
Why do you need a hardened PHP version? Just define a good set of rules in Selinux.

That's a load if I ever heard it.

php, by default has many flaws to it, such as allowing globals to be lax, allowing for poor coding. Obviously, something needs to be done there.

SElinux should be disabled, it's the linux version of "Cancel or allow", only more strict, more of a pain in the tail, and more problematic. If you want to spend hours learning and creating rulesets for selinux, then by all means, go for it. Others aren't going to bother.

There's a reason selinux is disabled by default with every major control panel install out there. That reason? It doesn't work, it's too restrictive, and it is just aweful.

Now, suhosin, on the other hand, I have never, EVER had an issue with when properly compiled into php. Don't use the module, use the patch. Compile php from the ground up, add in the suhosin patch, and any of the mailheader patches, and you'll be fine. Again, I've never, ever seen any problems with this setup, and I manage servers (and forums) that are pretty heavily used and modified.

TECK 04-22-2008 03:33 PM

I use Selinux on all my servers. Never had a problem, it is very easy to define solid security rules. You are right about the PHP flaws. However, those flaws appear ONLY when a programmer write BAD code. It is not PHP's language fault if the programmer knows nothing about coding. IMO, using Suhosin to prevent/correct an eventual mistake a coder can do is not a solution. Plus you know the patch is slowing down the code execution... a little but still does it. :)

There's a reason selinux is disabled by default with every major control panel install out there.
Any server admin I know will not touch with a 10 feet pole a control panel, like CPanel and other similar software. However, you are the server admin and you decide what is best for your box.

khb1st 06-17-2008 02:23 PM

although a little late to jump into this discussion I need to know from both of you

is either suhosin or selinux an absolute must on your server for security reasons

I have made my server installations using both, and I find suhosin to slow down the system tremendously, but I haven't tweaked the settings , yet, so that may change

security , these days , is of the utmost priority, and frankly, if it slows down up/downloads, that is no issue

I have done much reading and heard many opinions, but I would like a response (I feel they are both valuable) from each of you, asked kindly, and thanking in advance

please TECK and wolfstream


All times are GMT. The time now is 05:54 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.00969 seconds
  • Memory Usage 1,738KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete