vi /etc/php.ini
date.timezone = PRC #把前面的分號(hào)去掉,改為date.timezone = PRC
disable_functions = passthru,exec,system,chroot,scandir,chgrp,chown,shell_exec,proc_open,proc_get_status,ini_alter,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,stream_socket_server,escapeshellcmd,dll,popen,disk_free_space,checkdnsrr,checkdnsrr,getservbyname,getservbyport,disk_total_space,posix_ctermid,posix_get_last_error,posix_getcwd, posix_getegid,posix_geteuid,posix_getgid, posix_getgrgid,posix_getgrnam,posix_getgroups,posix_getlogin,posix_getpgid,posix_getpgrp,posix_getpid, posix_getppid,posix_getpwnam,posix_getpwuid, posix_getrlimit, posix_getsid,posix_getuid,posix_isatty, posix_kill,posix_mkfifo,posix_setegid,posix_seteuid,posix_setgid, posix_setpgid,posix_setsid,posix_setuid,posix_strerror,posix_times,posix_ttyname,posix_uname
#列出PHP可以禁用的函數(shù),如果某些程序需要用到這個(gè)函數(shù),可以刪除,取消禁用。
expose_php = Off #禁止顯示php版本的信息
display_errors = OFF #關(guān)閉錯(cuò)誤提示
register_globals = OFF #關(guān)閉注冊(cè)全局變量
magic_quotes_gpc = On #打開magic_quotes_gpc來防止SQL注入
log_errors = On #記錄錯(cuò)誤日志
error_log = /var/log/php/error_log.log #設(shè)置錯(cuò)誤日志存放目錄,文件必須允許apache用戶的和組具有寫的權(quán)限
#(chown apache.apache /var/log/php/error_log.log)
open_basedir = .:/tmp/ #設(shè)置表示允許訪問當(dāng)前目錄(即PHP腳本文件所在之目錄)和/tmp/目錄,可以防止php木馬跨站