Elxis CMS Forum

Support => General => Topic started by: ROUBOS on December 17, 2009, 16:44:38

Title: how important is url_fopen for Elxis?
Post by: ROUBOS on December 17, 2009, 16:44:38
Hi
I was just informed by the host provider, that the url_fopen can not be switched off

I have the entry in the .htaccess file : php_flag allow_url_fopen Off

but it is not allowed to work.

How important is it for the functionality of Elxis?
it's the only entry showing red when installing Elxis

thanks
Title: Re: how important is url_fopen for Elxis?
Post by: Ivan Trebješanin on December 17, 2009, 18:32:39
allow_url_fopen has nothing to do with Elxis functionality, but it is a major server security risk. It is also security risk for your site hosted on such server. However, Elxis Defender can protect you (properly configured) even if your server has allow_url_fopen on.
Title: Re: how important is url_fopen for Elxis?
Post by: datahell on December 17, 2009, 18:44:52
If allow_url_fopen is ON someone can open remote files as they were local:

fopen('http://www.other-site.com/files/file.txt');

Title: Re: how important is url_fopen for Elxis?
Post by: ROUBOS on December 17, 2009, 19:13:43
OK
I understand now. So that's ok. I know not to use this host for my personal site ;)

Will install Elxis and all will be ok then.

Thanks a lot.

Elxis is great and the help/support/community is great.

thanks
Title: Re: how important is url_fopen for Elxis?
Post by: ks-net on December 17, 2009, 22:21:15
Quote
Hi
I was just informed by the host provider, that the url_fopen can not be switched off

I have the entry in the .htaccess file : php_flag allow_url_fopen Off

but it is not allowed to work.

How important is it for the functionality of Elxis?
it's the only entry showing red when installing Elxis

thanks

as you can read at wiki http://wiki.elxis.org/wiki/PHP_settings
there are settings when server runs with mod_php  that can not be changed(* marked) through htaccess or httpd.conf .. they can only be changed in php.ini!

i have suggested you  suphp (in other post) for this(flexibility-security) and other reasons...

i will suggest(i know that you have already payed this server) in future to :
even find one suphp.. etc...  or find an elxis-hosting server.. there are some good.

vs servers can(wont) not disable functions that hundreds of software out there still uses... short_open_tags, fopen etc...


Title: Re: how important is url_fopen for Elxis?
Post by: ROUBOS on December 17, 2009, 22:40:36
yes you're right. I will look for an elxis supported server for my own website in the future.
this one is for someone else.

others recommended servers not in Greece. Using german ones. This "dn host" uses rackspace from the UK.
Title: Re: how important is url_fopen for Elxis?
Post by: rentasite on December 18, 2009, 11:36:09

How about  safe_mode on your server? is it OFF or ON ?
Title: Re: how important is url_fopen for Elxis?
Post by: Ivan Trebješanin on December 18, 2009, 14:04:20
... This "dn host" uses rackspace from the UK.

There are just 2 DC in Europe: Germany and Holland. So, every hosting company in EU has it's servers on some of these places. Ping your potential new server and look for Germany or Holland.
Title: Re: how important is url_fopen for Elxis?
Post by: ROUBOS on December 18, 2009, 15:14:25
OK thanks.

and safe mode on PHP is off. I can control that. Have it off so I can install some modules
Title: Re: how important is url_fopen for Elxis?
Post by: datahell on December 18, 2009, 20:03:02
There are just 2 DC in Europe: Germany and Holland. So, every hosting company in EU has it's servers on some of these places. Ping your potential new server and look for Germany or Holland.

This is not true. I know for sure that there are DCs in Italy, UK and France (I had a server in France before 5-6 years). I am sure that there will be in other countries too, Spain for example. There are even in Greece (dedicated and collocation - f.e. OTE).
Title: Re: how important is url_fopen for Elxis?
Post by: kebic on December 18, 2009, 21:12:41
In Hungary has a good DC.
Title: Re: how important is url_fopen for Elxis?
Post by: rentasite on December 18, 2009, 21:18:50
There are even in Greece (dedicated and collocation - f.e. OTE).

Right! Also in Agios Stefanos (near Athens) ...Forthnet DC (ex Internet Hellas DC). Stay away from that. The guys on Fridays they close their "shop" and return back to work on Mondays.
 
Title: Re: how important is url_fopen for Elxis?
Post by: Ivan Trebješanin on December 18, 2009, 22:30:36
I know there are small DCs all around, even here, in Serbia some guys are trying to run one, but I'm talking about serious competitors.
Title: Re: how important is url_fopen for Elxis?
Post by: datahell on December 18, 2009, 23:31:29
Some Greek DCs are huge, OTE is one of the largest IT companies in Europe (owns serbian telecom company too). The problem with them is that they are VERY expensive, that's why we search for servers abroad. But you will find very good and cheap servers in many countries especially in France and Italy. For instance I had 2 excellent and very cheap servers at OVH (france) that I used for streaming. Italy has also some very good DCs and it is very close to us (better solution than Germany for us - Greeks and Serbs).

Some links I remember to French DCs:
http://www.ovh.com
http://www.gandi.net

Title: Re: how important is url_fopen for Elxis?
Post by: rentasite on December 18, 2009, 23:35:52
PowerVPS rulez!  Located @ USA.  You may ping them and see

* Washington, DC - 74.200.69.93
* Chicago, IL - 74.200.92.66

I don't change them!  ;)

A short list of the companies which utilize this same network (Equinix) are: IBM, Google, Sony Online, General Electric, Electronic Arts, Primedia/About.com, Hotwire, Yahoo!, Microsoft, XMRadio, and YouTube.