From 384eee9344a50dc35695e4adc22e67a30508ac01 Mon Sep 17 00:00:00 2001 From: jvoisin Date: Mon, 26 Feb 2018 11:15:09 +0100 Subject: Improve the previous commit --- config/default.rules | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'config') diff --git a/config/default.rules b/config/default.rules index 8ac4498..7e3ee53 100644 --- a/config/default.rules +++ b/config/default.rules @@ -5,7 +5,7 @@ sp.disable_function.function("chmod").param("mode").value_r("^[0-9]{2}[67]$").dr sp.disable_function.function("mail").param("additional_parameters").value_r("\\-").drop(); # Since it's now burned, me might as well mitigate it publicly -sp.disable_function.function("putenv").param("setting").value_r("LD_PRELOAD").drop() +sp.disable_function.function("putenv").param("setting").value_r("LD_").drop() ##Prevent various `include`-related vulnerabilities sp.disable_function.function_r("^(?:require|include)_once$").value_r("\\.(?:php|php7|inc|tpl)$").allow(); -- cgit v1.3