<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[刘新修]]></title> 
<link>http://pic1.liuxinxiu.com:80/index.php</link> 
<description><![CDATA[刘新修的个人博客 (Liuxinxiu'S Blog)]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[刘新修]]></copyright>
<item>
<link>http://pic1.liuxinxiu.com:80/php_disable_functions/</link>
<title><![CDATA[PHP禁止一些有潜在威胁性的函数]]></title> 
<author>刘新修 &lt;admin@yourname.com&gt;</author>
<category><![CDATA[H5/JS/CSS]]></category>
<pubDate>Fri, 20 Sep 2013 11:14:40 +0000</pubDate> 
<guid>http://pic1.liuxinxiu.com:80/php_disable_functions/</guid> 
<description>
<![CDATA[ 
	<p>根据电脑51我改动过的：</p><div class="codeText"><div class="codeHead">PHP代码</div><ol start="1" class="dp-c"><li class="alt"><span><span>disable_functions = phpinfo,system,</span><span class="func">passthru</span><span>,</span><span class="func">eval</span><span>,</span><span class="func">exec</span><span>,</span><span class="func">chroot</span><span>,</span><span class="func">chgrp</span><span>,</span><span class="func">chown</span><span>,scandir,shell_exec,proc_get_status,</span><span class="func">ini_alter</span><span>,</span><span class="func">ini_alter</span><span>,</span><span class="func">ini_restore</span><span>,dl,pfsockopen,openlog,syslog,</span><span class="func">readlink</span><span>,symlink,popepassthru,stream_socket_server,fsocket,</span><span class="func">fsockopen</span><span>，popen,proc_open,opendir&nbsp;&nbsp;</span></span></li></ol></div><p><span style="color: rgb(0, 0, 255);">disable_functions = system,passthru,exec,shell_exec,phpinfo,get_current_user,ini_restore,dl,scandir,popen,proc_open,opendir</span></p><p>其中opendir这个是文件浏览的重要函数，禁了这个，大部分PHP木马都没门了。</p><p>不过会对一些正常的PHP有时候会造成影响，但是不影响正常使用。比如DZ论坛的后台 文件校验、运行记录等。就有影响了。。。</p><p>更严格的一些函数：</p><div class="codeText"><div class="codeHead">PHP代码</div><ol start="1" class="dp-c"><li class="alt"><span><span>disable_functions = phpinfo,system,</span><span class="func">passthru</span><span>,</span><span class="func">exec</span><span>,</span><span class="func">chroot</span><span>,</span><span class="func">chgrp</span><span>,</span><span class="func">chown</span><span>,scandir,shell_exec,proc_get_status,</span><span class="func">ini_alter</span><span>,</span><span class="func">ini_alter</span><span>,</span><span class="func">ini_restore</span><span>,dl,pfsockopen,openlog,syslog,</span><span class="func">readlink</span><span>,symlink,popepassthru,stream_socket_server,get_current_user,leak,putenv,popen,proc_open,opendir&nbsp;&nbsp;</span></span></li></ol></div><p>&nbsp;</p>
]]>
</description>
</item><item>
<link>http://pic1.liuxinxiu.com:80/php_disable_functions/#blogcomment</link>
<title><![CDATA[[评论] PHP禁止一些有潜在威胁性的函数]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://pic1.liuxinxiu.com:80/php_disable_functions/#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>