[CentOS] Hardened PHP? Suhosin patch?

Johnny Hughes johnny at centos.org
Fri Feb 15 17:03:04 UTC 2008


Niki Kovacs wrote:
> Hi,
> 
> I'm running a few PHP-based apps on our server (PMB, SPIP, Joomla, 
> PHPMyAdmin), and I'm not always comforted about security. I don't know 
> the details, but many a security expert frowns when it comes to PHP.
> 
> Now I just stumbled over this:
> 
> http://www.hardened-php.net/suhosin.127.html
> 
> Has anyone already tried this out? An opinion about it? Is it worth it?
> 
> Since I have to rebuild PHP anyway (because I need some specific modules 
> that can only be obtained by rebuilding it), it wouldn't be much of a 
> hassle. But I'm curious about the experts' opinion here.
> 

http://www.hughesjr.com/content/view/21/1/

That explains how to install in centos-4 and centos-5.

Thanks,
Johnny Hughes

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 252 bytes
Desc: OpenPGP digital signature
URL: <http://lists.centos.org/pipermail/centos/attachments/20080215/3e642207/attachment.sig>


More information about the CentOS mailing list