support for register_globals = Off

Anything that you think should be in Cacti.

Moderators: Developers, Moderators

Post Reply
JustinHoMi
Posts: 17
Joined: Mon Oct 07, 2002 3:42 pm

support for register_globals = Off

Post by JustinHoMi »

Would the designers consider supporting register_globals = Off? I'd love to run cacti, but having it on is too much of a security hole for our servers.

Justin
raX
Lead Developer
Posts: 2243
Joined: Sat Oct 13, 2001 7:00 pm
Location: Carlisle, PA
Contact:

Post by raX »

I know, if only I had known this way back when :-?

Anyhow since this is sort of an "overhaul feature", it will have to wait until 0.8. Don't worry though, so far I have not used any global variables when working with 0.8. All it will take is a little testing at the end, and everyone should be happy (and secure :wink:).

-Ian
dlippolt
Posts: 2
Joined: Sun Nov 17, 2002 1:55 am

Re: support for register_globals = Off

Post by dlippolt »

JustinHoMi wrote:Would the designers consider supporting register_globals = Off? I'd love to run cacti, but having it on is too much of a security hole for our servers.

Justin
until .8 (or whenever globals off supported) devote its own apache add an additional http auth password to the entire cacti site and run it over ssl, so you only have to worry about YOUR users attempting php hacks.
Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests