FORUM HOME | WHUK BLOG   
WEB HOSTING UK AFFORDABLE WEBSITE HOSTING SERVICES IN UNITED KINGDOM
PHP LINUX SHARED HOSTING WINDOWS ASP.NET HOSTING PACKAGES
ECOMMERCE HOSTING ASP MSSQL MS ACCESS ODBC FRONTPAGE HOSTING
CPANEL WHM FANTASTICO RESELLER DEDICATED SERVER WEB HOSTING
CHEAP PLESK CPANEL HTML MYSQL BEST UK VPS HOSTING COMPANY
CHEAP RELIABLE UK HOSTING PROVIDER SINCE 2001
MANAGED WEB HOSTING SERVICE
AFFORDABLE WEBSITE HOSTING SERVICES IN UNITED KINGDOM

Web Hosting UK Forums | Linux Windows Dedicated Server and cPanel VPS Hosting Forum » Web Hosting and Domains » CMS Hosting

Reply
 
LinkBack Thread Tools Display Modes

  #1 (permalink)  
Old 24-10-11, 01:06 PM
new member
 
Join Date: Sep 2011
Posts: 3
Default Joomla, popen() and security.

I would like to use a component and plugin called PDF Indexer v3.3 to index the PDFs on my Joomla site and make them available to the search function.

Unfortunatley it dos not work because popen() is one of the disabled functions in php.ini.

This function is needed to open the pdf files from within the Joomla admin console so that they can be indexed. I have read various articles about the security risks using popen(), but these all appear to relate to it's use with information filled in by users on web forms and the ability to trick the command to do something nasty. As popen() won't be interfaced with the public, I don't think this will be a problem, but not being even an intermediate user, I could be wrong.

So, is it possible to have popen() removed from the discabled_functions list?

Regards,
Simon.
Reply With Quote

  #2 (permalink)  
Old 24-10-11, 01:26 PM
Ross's Avatar
Sales Team
 
Join Date: Nov 2010
Posts: 377
Send a message via MSN to Ross Send a message via Skype™ to Ross
Default

Quote:
Originally Posted by quill1959 View Post
I would like to use a component and plugin called PDF Indexer v3.3 to index the PDFs on my Joomla site and make them available to the search function.

Unfortunatley it dos not work because popen() is one of the disabled functions in php.ini.

This function is needed to open the pdf files from within the Joomla admin console so that they can be indexed. I have read various articles about the security risks using popen(), but these all appear to relate to it's use with information filled in by users on web forms and the ability to trick the command to do something nasty. As popen() won't be interfaced with the public, I don't think this will be a problem, but not being even an intermediate user, I could be wrong.

So, is it possible to have popen() removed from the discabled_functions list?

Regards,
Simon.
Allow me some time to check this. I will post a update shortly.
__________________
Webhosting UK :: Reseller Hosting | Fully Managed Dedicated Server
"Refer and Win " a Hosting package and domain name
Follow us on Social Networks like Facebook, Twitter and Google+
Reply With Quote

  #3 (permalink)  
Old 24-10-11, 01:36 PM
Ross's Avatar
Sales Team
 
Join Date: Nov 2010
Posts: 377
Send a message via MSN to Ross Send a message via Skype™ to Ross
Default

Hello Simon,

Please check the Ticket: USB-781-75121. You can update the same ticket if you have any issues.
__________________
Webhosting UK :: Reseller Hosting | Fully Managed Dedicated Server
"Refer and Win " a Hosting package and domain name
Follow us on Social Networks like Facebook, Twitter and Google+
Reply With Quote

Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump


All times are GMT. The time now is 02:50 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Copyright 2001-2010 Web Hosting UK. All rights reserved.
Web Hosting UK Forum





Site Map

Shared Cloud
Shared Cloud From £1

Affiliate Program
Earn up to £300 Per Sale

Dedicated Servers
Dedicated Server Hosting

Cloud Hosting
Cloud Server Hosting

Load Balanced Server
Load Balancing Server

VPS Hosting
Linux VPS Hosting

Windows VPS
Windows 2003 VPS

Zimbra Hosting
Zimbra Email Hosting

cPanel Hosting
Shared Linux Hosting

Windows Hosting
Shared Windows Hosting

Coldfusion Hosting
Windows Coldfusion Hosting

cPanel Reseller Hosting
Reseller Hosting

Windows Reseller
Windows Reseller Hosting

Email Web Hosting
Email Hosting

Semi-Dedicated Server
Semi-Dedicated Hosting

Remote Backup Plans
Offsite Backup Service


cpanel hosting
Knowledgebase Articles

Pre-Sales Question
Web Hosting FAQ's

Dedicated Hosting
Dedicated Server FAQ's

Virtual Private Servers
VPS Hosting

PHP MySQL Hosting
cPanel Hosting

Windows Hosting
ASP MSSQL Hosting

Domain Name
Domain registration FAQ's

CMS Hosting
CMS Hosting FAQ's

Payment Gateways
Payment FAQ's


Support Tutorials

cPanel Tutorials
cPanel Flash Tutorials

Wordpress Tutorials
Wordpress Flash Tutorials

Plesk Tutorials
Plesk Flash Tutorials

PhpMyadmin Tutorials
PhpMyadmin Flash Tutorials

Drupal Tutorials
Drupal Flash Tutorials

Mambo Tutorials
Mambo Flash Tutorials

Joomla Tutorials
Joomla Flash Tutorials

More Hosting Tutorials