Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Security

General questions about VestaCP
Post Reply
  • Print view
Advanced search
18 posts
  • Previous
  • 1
  • 2
joni
Posts: 60
Joined: Sat Aug 27, 2016 9:22 pm

Os: Ubuntu 18x
Web: nginx + php-fpm
Re: Security
  • Quote

Post by joni » Mon Oct 22, 2018 12:38 pm

imperio wrote: ↑
Sun Oct 21, 2018 8:24 pm
You can disable some php functions, read the message from chrisf
I am geting this
[root@thequeen ~]# disable_functions = "exec, system"
-bash: disable_functions: command not found
[root@thequeen ~]#
Top

chrisf
Posts: 49
Joined: Sat Oct 13, 2018 6:25 pm

Os: Ubuntu 16x
Web: apache + nginx
Re: Security
  • Quote

Post by chrisf » Mon Oct 22, 2018 12:41 pm

Ummm. That's because it's a PHP ini directive?

Google it.
Top

joni
Posts: 60
Joined: Sat Aug 27, 2016 9:22 pm

Os: Ubuntu 18x
Web: nginx + php-fpm
Re: Security
  • Quote

Post by joni » Mon Oct 22, 2018 12:51 pm

chrisf wrote: ↑
Mon Oct 22, 2018 12:41 pm
Ummm. That's because it's a PHP ini directive?

Google it.
Thx, should I place it in etc/php.ini file on the server ? I googled it actually..or in every single account I should set php.ini file
Top

chrisf
Posts: 49
Joined: Sat Oct 13, 2018 6:25 pm

Os: Ubuntu 16x
Web: apache + nginx
Re: Security
  • Quote

Post by chrisf » Mon Oct 22, 2018 1:21 pm

That depends on your setup.

If its straight out the box, I believe Vesta uses a single php.ini (I have switched to php-fpm).

Easiest way to find out. Go to your domains root folder and add this script:

phpInfo.php

Code: Select all

<?php phpinfo(); ?>
Then visit it in your browser:

http://yoursite.com/phpInfo.php

In the first section it will have what config (ini) file is being used.

Add it there. You may need to restart the webserver if using standard apache2.

Code: Select all

service apache2 restart
:-)
Top

joni
Posts: 60
Joined: Sat Aug 27, 2016 9:22 pm

Os: Ubuntu 18x
Web: nginx + php-fpm
Re: Security
  • Quote

Post by joni » Mon Oct 22, 2018 3:15 pm

chrisf wrote: ↑
Mon Oct 22, 2018 1:21 pm
That depends on your setup.

If its straight out the box, I believe Vesta uses a single php.ini (I have switched to php-fpm).

Easiest way to find out. Go to your domains root folder and add this script:

phpInfo.php

Code: Select all

<?php phpinfo(); ?>
Then visit it in your browser:

http://yoursite.com/phpInfo.php

In the first section it will have what config (ini) file is being used.

Add it there. You may need to restart the webserver if using standard apache2.

Code: Select all

service apache2 restart
:-)
chrisf, thx, can you please point me how I can check up the result of what have I done..how can I know that these functions are disabled ?

Thx again
Top

chrisf
Posts: 49
Joined: Sat Oct 13, 2018 6:25 pm

Os: Ubuntu 16x
Web: apache + nginx
Re: Security
  • Quote

Post by chrisf » Mon Oct 22, 2018 5:39 pm

Run that same test script, scroll down to where it says disabled functions. If it is your list, it's working.

Anytime you change anything in php that phpInfo.php will let you know if it is working for that domain. :-)

It lists every function of php and it's setting.
Top

joni
Posts: 60
Joined: Sat Aug 27, 2016 9:22 pm

Os: Ubuntu 18x
Web: nginx + php-fpm
Re: Security
  • Quote

Post by joni » Fri Oct 26, 2018 5:56 pm

Thank you chrisf if you have aome other security tip for shared hostings, please share it here, it is a great topic and great contribution from you!
Top

arafatx
Posts: 25
Joined: Tue Aug 11, 2015 4:51 pm

Re: Security
  • Quote

Post by arafatx » Thu Jul 11, 2019 1:46 am

I respect the marketing team, because they tried so hard to build trust for the product that doesn't really fit in security.

One reason that I feel unsafe to use Vesta back in 2018 is when the big boss told everyone that, they are not gonna rewrite codes for basic security practice (changing admin username or lock it). The response was "No!" we won't fix that coz of thousand line of codes.

People think that this is a one-man-show project because of lack response. If you need the product become big, find investors, find manpowers, rewrite codes, most important is listen to users and their critique. If you think a critique is an insult then, stop. It's over.

I'm currently on premium license for directadmin and cpanel. I came here only to visit any news on security since long time ago I haven't touched it. You see, I have the feeling this product is going to be the best but only you can change my perspective.
Top


Post Reply
  • Print view

18 posts
  • Previous
  • 1
  • 2

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

cron

Login  •  Register

I forgot my password