Twitter (FxNxRl)Google SearchMore ContentSite RankMy FOSS Work |
How to: Ubuntu PHP Remove SuhosinWednesday, December 10. 2008Trackbacks
Trackback specific URI for this entry
No Trackbacks
Comments
Display comments as
(Linear | Threaded)
I've submited a bug report on this.
Probably do no good but you never know. https://bugs.launchpad.net/ubuntu/+source/php5/+bug/315507 i got this error
gpg: skipped "server-admin ": secret key not available gpg: [stdin]: clearsign failed: secret key not available debsign: gpg error occurred! Aborting.... debuild fatal error at line 1174: running debsign failed I got this error, too
gpg: keyring `/home/webnet/.gnupg/secring.gpg' created gpg: skipped "webnet ": secret key not available gpg: [stdin]: clearsign failed: secret key not available debsign: gpg error occurred! Aborting.... debuild: fatal error at line 1250: running debsign failed If you look in the deb folder the files will be have made even with the debsign error.
If you've followed this guide the files will be up one directory. Thank you for this detailed guide. How frustrating it is to see that the Ubuntu maintainers don't understand that Suhosin breaks tons of shit.
i am compiling that right now and i hope it will fix problems with apc_fetch and uploading file progress..
will comment when i am done.. iit makes long time This has been driving me nuts. I was already in the process of the re-compile sans suhosin looking for an already compile .deb. I'm doing this for 9.04/64, but the problem is the typical 52 packages with dependencies, and then Ubuntu upgrades and, ....
I think this is a great tip. In fact, I'm using it now because I'm setting up an intentionally insecure site for demonstration purposes.
While Suhosin certainly can 'break shit', I'd argue that it's better to learn to work around it than to remove it all together. But that's me, a security guy. Using PHP is playing with a loaded weapon if you are not very very careful. If you ('you' not being the author but the reader) do remove Suhosin, please, for the love of god, do some pen testing on your site and make sure you look for flaws. Otherwise you'll be owned very quickly when that trouble could have been avoided. W3AF would serve as a great 'sanity' check for developers who go it alone (or anyone else). All the best. Indeed, there are now reasonable instructions available that make it possible to disable the more odious features of Suhosin and keep nice things like buffer overflow checking.
I recommend that people use this approach rather than remove the package altogether. Still, my objection to these sorts of tools is not only the false positives, but the false sense of security they generate. Many a site owner thinks they're 100% protected because they have some array of tools and filters configured. Armed with this illusion, they feel comfortable in ignoring vulnerability reports and critical upgrades, and then are upset when their sites get hacked. |
Net NeutralityCategoriesRecent EntriesPlug for SpeedTest.net, Raspberry for Bell (revised)
Idea: Typo Swap Key Let's Just Call it the Canadian Conference Board of Incompetence A Site that Provides De-Fluffed Transcipts of Web Content Nigerian Style Fraud Via Facebook Enough with "Toilet Paper Pitch" Web Sites! Realizing Complex Sculptural Art with Technology Social Media: Why Facebook; Why Twitter? Geek BlogOn Development Teams
Amazing Code Repository Visualization (Joomla) MySQL's Post-Oracle Future On the Enforcability of the GPL More Controversy: the Joomla Extensions Directory (JED) and the GPL Simplifying Joomla Template Layouts How to: Ubuntu PHP Remove Suhosin Joomla 1.5.8 is... is what?? "IBM May Quit Technology Standards Bodies" WSJ Screams In Search of an Application Framework: PHP GTK Python XULRunner LinksAdministrationTop Exitswww.michaelgeist.ca (45)
www.conferenceboard.ca (8) www.extensionprofessionals.com (8) www.theglobeandmail.com (7) www.ambitonline.com (6) www.google.com (6) consumerist.com (5) ubuntuforums.org (5) www.groklaw.net (4) www.mozilla.org (4) Comment SubmissionsAll comments are moderated. If you submit comment spam, you consent to having your text edited to reflect extremely badly on the site you're attempting to promote. A spam comment is both consent and an explicit invitation to have your text edited to include insults, untruths, derogatory remarks, slurs, and so on. This consent applies even if a third party added the comment, whether or not you had any direct or indirect involvement with it. You also consent to having all communications related to any comment disclosed on this site and elsewhere.
Finally, should you choose to ignore this and undertake any action to have comments removed, you agree to compensate us and/or anyone we designate at the rate of US$2,500 per hour, in addition to any legal costs, be they reasonable or otherwise. In short: spam at your expense and peril. |