From b921322ce5faa5c49a14d71bb37f855b0634de0e Mon Sep 17 00:00:00 2001 From: jvoisin Date: Thu, 18 Aug 2022 20:50:57 +0200 Subject: Fix the default configuration on php7.4+ --- config/default.rules | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/config/default.rules b/config/default.rules index a19d678..232197a 100644 --- a/config/default.rules +++ b/config/default.rules @@ -112,8 +112,12 @@ sp.disable_function.function("curl_setopt").param("option").value("64").drop().a sp.disable_function.function("curl_setopt").param("option").value("81").drop().alias("Please don't turn CURLOPT_SSL_VERIFYHOST off."); # File upload -sp.disable_function.function("move_uploaded_file").param("destination").value_r("\\.ph").drop(); -sp.disable_function.function("move_uploaded_file").param("destination").value_r("\\.ht").drop(); +# On old PHP7 versions +#sp.disable_function.function("move_uploaded_file").param("destination").value_r("\\.ph").drop(); +#sp.disable_function.function("move_uploaded_file").param("destination").value_r("\\.ht").drop(); +# On PHP7.4+ +sp.disable_function.function("move_uploaded_file").param("new_path").value_r("\\.ph").drop(); +sp.disable_function.function("move_uploaded_file").param("new_path").value_r("\\.ht").drop(); # Logging lockdown sp.disable_function.function("ini_set").param("varname").value_r("error_log").drop() -- cgit v1.3