Jump to content

Shell or shell_exec in production web server? safe?


SJ77

Recommended Posts

Posted
4 hours ago, bfarber said:

I would not recommend leaving shell_exec enabled if you didn't have a specific reason.

seems I need it to run ff_mpeg.  I am trying to weigh the risk verses reward here.

Posted

Well, in that case you have a specific reason. If you have a specific reason, and the command isn't open to injection, that's fine. It's there for a purpose. Most clients do not need it, and subsequently I would recommend disabling it.

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...