Register Members List Search Today's Posts Mark Forums Read

Reply
 
Thread Tools
  #1  
Old 05 Apr 2008, 19:24
Jase2 Jase2 is offline
 
Join Date: Dec 2007
Suhosin

Hi all,

I ran a diagnostics, and it says: Suhosin Module Loaded Yes.

Suhosin can limit the amount of data submitted and encrypt cookies causing problems with several aspects of vBulletin.
Anyone know how to disable this?
Reply With Quote
  #2  
Old 05 Apr 2008, 20:12
snakes1100 snakes1100 is offline
 
Join Date: Dec 2001
Real name: Anthony
Unless you can modify php.ini you cant, unless your host allows php.ini over riding per host, ask your host.
Reply With Quote
  #3  
Old 05 Apr 2008, 20:21
Jase2 Jase2 is offline
 
Join Date: Dec 2007
Definitely causing issues.

I'll try increasing:

* php_value suhosin.post.max_vars
* php_value suhosin.request.max_vars
Reply With Quote
  #4  
Old 05 Apr 2008, 20:35
Opserty Opserty is offline
 
Join Date: Apr 2007
Search vBulletin.com I remember a post there a while back defining the settings required.
Reply With Quote
  #5  
Old 05 Apr 2008, 20:45
Jase2 Jase2 is offline
 
Join Date: Dec 2007
http://www.vbulletin.com/forum/showt...82#post1329782
Reply With Quote
  #6  
Old 06 Apr 2008, 11:22
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Moved to Server Management.
__________________
Marco van Herwaarden
Ex vBulletin.org Coordinator
Reply With Quote
  #7  
Old 13 Apr 2008, 07:50
TECK's Avatar
TECK TECK is offline
 
Join Date: Dec 2001
Real name: Floren Munteanu
Take off Suhosin, it is designed to slowdown your server.
Why do you need a hardened PHP version? Just define a good set of rules in Selinux.
__________________
Floren Munteanu
Axivo Inc.
Axivo Community - Visit the forums to find out more about us
Why Queued - My personal blog
Reply With Quote
  #8  
Old 22 Apr 2008, 14:44
wolfstream wolfstream is offline
 
Join Date: Jan 2003
Real name: Tom Whiting
Originally Posted by TECK View Post
Take off Suhosin, it is designed to slowdown your server.
Why do you need a hardened PHP version? Just define a good set of rules in Selinux.
That's a load if I ever heard it.

php, by default has many flaws to it, such as allowing globals to be lax, allowing for poor coding. Obviously, something needs to be done there.

SElinux should be disabled, it's the linux version of "Cancel or allow", only more strict, more of a pain in the tail, and more problematic. If you want to spend hours learning and creating rulesets for selinux, then by all means, go for it. Others aren't going to bother.

There's a reason selinux is disabled by default with every major control panel install out there. That reason? It doesn't work, it's too restrictive, and it is just aweful.

Now, suhosin, on the other hand, I have never, EVER had an issue with when properly compiled into php. Don't use the module, use the patch. Compile php from the ground up, add in the suhosin patch, and any of the mailheader patches, and you'll be fine. Again, I've never, ever seen any problems with this setup, and I manage servers (and forums) that are pretty heavily used and modified.
Reply With Quote
  #9  
Old 22 Apr 2008, 16:33
TECK's Avatar
TECK TECK is offline
 
Join Date: Dec 2001
Real name: Floren Munteanu
I use Selinux on all my servers. Never had a problem, it is very easy to define solid security rules. You are right about the PHP flaws. However, those flaws appear ONLY when a programmer write BAD code. It is not PHP's language fault if the programmer knows nothing about coding. IMO, using Suhosin to prevent/correct an eventual mistake a coder can do is not a solution. Plus you know the patch is slowing down the code execution... a little but still does it.

There's a reason selinux is disabled by default with every major control panel install out there.
Any server admin I know will not touch with a 10 feet pole a control panel, like CPanel and other similar software. However, you are the server admin and you decide what is best for your box.
__________________
Floren Munteanu
Axivo Inc.
Axivo Community - Visit the forums to find out more about us
Why Queued - My personal blog
Reply With Quote
  #10  
Old 17 Jun 2008, 15:23
khb1st khb1st is offline
 
Join Date: Mar 2008
although a little late to jump into this discussion I need to know from both of you

is either suhosin or selinux an absolute must on your server for security reasons

I have made my server installations using both, and I find suhosin to slow down the system tremendously, but I haven't tweaked the settings , yet, so that may change

security , these days , is of the utmost priority, and frankly, if it slows down up/downloads, that is no issue

I have done much reading and heard many opinions, but I would like a response (I feel they are both valuable) from each of you, asked kindly, and thanking in advance

please TECK and wolfstream
Reply With Quote
  #11  
Old 17 Jun 2008, 16:20
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
A short answer: If you are only running vBulletin, then absolutly a No

Which security holes do you currently have that you want to stop by one of these?
__________________
Marco van Herwaarden
Ex vBulletin.org Coordinator
Reply With Quote
  #12  
Old 17 Jun 2008, 18:08
khb1st khb1st is offline
 
Join Date: Mar 2008
I am only concerned of stopping ANY potential holes

many people out there like to give opinions, and it seems a good portion believe suhosin is essential for possinle php problems (which I have none , so far)

the addition of suhosin (as I mentioned) has slowed down some processes, very obviously, and I just wanted to hear a few comments from people , who I feel have more knowledge about this

and thanks Marco for a swift and pointed reply
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
Forum Jump


New To Site? Need Help?

All times are GMT. The time now is 15:19.

Layout Options | Width: Wide Color: