Forum Moderators: coopster

Message Too Old, No Replies

Using Suhosin for hardening?

         

foxfox

5:33 am on Dec 25, 2006 (gmt 0)

10+ Year Member



If using the latest 5.2 PHP, is hardening considered useful and a must for production server?

coopster

3:39 pm on Dec 25, 2006 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



Only you can answer that question ;)

[hardened-php.net...]

foxfox

4:38 pm on Dec 25, 2006 (gmt 0)

10+ Year Member



it is from the view of `Suhosin`...

foxfox

4:40 pm on Dec 25, 2006 (gmt 0)

10+ Year Member



for example, it said

>> bufferoverflows and related vulnerabilities in the Zend Engine

but aren't these bugs fixed in the latest version of PHP?

coopster

5:05 pm on Dec 25, 2006 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



it is from the view of `Suhosin`...

Read more carefully though ...


The answer to this question depends on what your usage of PHP is.

emphasis added

The page itself answers your second question too, immediately after the sentence you quoted it states ...


History has shown that several of these bugs have always existed in previous PHP versions.

You are going to have to determine whether or not you want/need it for your installation. As stated earlier, you are your best resource for making that determination.