Go Back   Defender Hosting Forums > PowerVPS Virtual Private Servers > Linux VPS - Security and Tuning

Linux VPS - Security and Tuning Security and Tuning Discussion for Linux Virtual Private Servers based on Virtuozzo by SWsoft

Reply
 
Thread Tools Display Modes

  #1  
Old 01-15-2006, 11:00 PM
skyblu
Guest
 
Posts: n/a
Default How do I install Hardened PHP

Hi,

I want to install this Hardened PHP patch but don't know how.
http://www.hardened-php.net/downloads.13.html

Can someone please tell me what I need to do? I'm on CPanel and normally use YUM for updates.

TIA
Reply With Quote

  #2  
Old 01-15-2006, 11:54 PM
sdjl's Avatar
sdjl sdjl is offline
Senior Member
 
Join Date: Dec 2005
Location: London, UK.
Posts: 349
sdjl is on a distinguished road
Send a message via AIM to sdjl
Default

Well, if their download names are hinting at what you should do, it would be to use the patch command via SSH to patch certain PHP files.
That's just a guess..

David
Reply With Quote

  #3  
Old 01-16-2006, 12:50 AM
skyblu
Guest
 
Posts: n/a
Default

gpg --import http://www.hardened-php.net/hardened...nature-key.asc
wget http://www.hardening-patch-4.4.1-0.4.8.patch.gz
gunzip hardening-patch-4.4.1-0.4.8.patch.gz
cd php-4.4.1
patch -p 1 < ../hardened-php-4.4.1-0.4.8.patch

Is this how it would be done?

But i read this, so maybe I can't install it. What does everyone think?

Hardened-PHP is not binary compatible to normal PHP anymore. If you want to use closed source extension with it, you must ask your vendor, to provide some linked against H-PHP. Open Source extensions will work like before, but need a recompile.
Reply With Quote

  #4  
Old 01-18-2006, 01:30 AM
Hvu
Guest
 
Posts: n/a
Default

I dont believe you can use Hardened-PHP with cpanel. Since cpanel updates its software i believe. I have never admin a cpanel server before but with Directadmin you would just patch the files and compile. Might wanna ring up support.
Reply With Quote

  #5  
Old 01-22-2006, 02:02 AM
skyblu
Guest
 
Posts: n/a
Default

Thanks Hvu,
i've decided against adding it. At least, not right now, the mod_sec rules seem to be doing a pretty good job.
Reply With Quote

  #6  
Old 01-26-2006, 04:10 PM
elix elix is offline
Senior Member
 
Join Date: Jun 2005
Posts: 787
elix is on a distinguished road
Default Re: How do I install Hardened PHP

Quote:
Originally Posted by Hvu
I dont believe you can use Hardened-PHP with cpanel. Since cpanel updates its software i believe. I have never admin a cpanel server before but with Directadmin you would just patch the files and compile. Might wanna ring up support.
cPanel doesn't auto update PHP.

You can easily run your own PHP compilations.
__________________
Got clue?
Reply With Quote

  #7  
Old 08-09-2006, 05:44 AM
asterisk asterisk is offline
Senior Member
 
Join Date: Oct 2005
Posts: 248
asterisk is on a distinguished road
Default Re: How do I install Hardened PHP

I was thinking of using Hardened-PHP too. But it seems it's not compatible as skyblu has pointed out, with closed source extensions such as Zend Optimizer. Bummer. Although Eaccelerator works with it.

I'm wondering if it would work with PHPSuExec though.

Last edited by asterisk; 08-09-2006 at 05:55 AM..
Reply With Quote

  #8  
Old 08-09-2006, 08:10 PM
elix elix is offline
Senior Member
 
Join Date: Jun 2005
Posts: 787
elix is on a distinguished road
Default Re: How do I install Hardened PHP

The ideal way to run this would be to have your own compile of PHP (which is easily done via cPanel, by the way, I do it in my boxes with no problems, I never use easyapache) and then just patch the source before you compile it. You will then have the hardened PHP...you can do this on a Plesk VPS as well.
__________________
Got clue?
Reply With Quote

  #9  
Old 08-09-2006, 09:27 PM
asterisk asterisk is offline
Senior Member
 
Join Date: Oct 2005
Posts: 248
asterisk is on a distinguished road
Default Re: How do I install Hardened PHP

Thanks for the pointer, elix. I will certainly try that out soon, compiling from source and pre-patching it.

Regarding mod_sec, skyblu, how useful did you find it?

Until recently, mod_sec worked well for me too but that was because websites served were plain vanilla. When more complex php scripts were served allowing user-input, it seems like the thing's on hair-trigger. So I just disabled it for the respective directories.

If only they were like cPanel, having five different trees from stable to edge indicating the false-positive likelihood of the rules.
Reply With Quote

  #10  
Old 08-10-2006, 03:00 PM
elix elix is offline
Senior Member
 
Join Date: Jun 2005
Posts: 787
elix is on a distinguished road
Default Re: How do I install Hardened PHP

Uhh...for mod_security you can choice what ruleset you use............I suggest you read up on what modsecurity is on www.modsecurity.org... its the framework it doesn't actually have rules by default, the rules are all up to you
__________________
Got clue?

Last edited by Robert; 08-10-2006 at 04:13 PM..
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HELP!! VPS Processes atnetsolutions Linux VPS - General 7 11-08-2006 09:07 AM
The Black Zone doctoradel Linux VPS - General 8 07-19-2006 10:51 AM
[HOW TO] Install APC (Alternative PHP Cache) Zaf Linux VPS - HOWTOs and FAQs 87 06-25-2006 02:30 PM
HOWTO Manual Windows PHP Install Milovan Windows VPS - HOWTOs and FAQs 2 06-01-2006 05:25 PM
PayPal SDK: Need Curl and OpenSSL into PHP.. tm2000 Linux VPS - cPanel 5 10-26-2005 11:07 AM



All times are GMT -4. The time now is 04:18 AM.


vBulletin skin developed by: eXtremepixels
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright Defender Technologies Group, LLC 2006