Browse Source

Added max_input_vars directive to prevent attacks based on hash collisions

pull/12/head
Dmitry Stogov 15 years ago
parent
commit
b8a08bf263
  1. 5
      UPGRADING
  2. 3
      php.ini-development
  3. 3
      php.ini-production

5
UPGRADING

@ -163,6 +163,11 @@ UPGRADE NOTES - PHP 5.3
xsl.security_prefs. This option will be marked as deprecated in 5.4 again.
Use the method XsltProcess::setSecurityPrefs($options) there.
- the following new directives were added
- max_input_vars - specifies how many GET/POST/COOKIE input variables may be
accepted. default value 1000.
=============
5. Deprecated
=============

3
php.ini-development

@ -457,6 +457,9 @@ max_input_time = 60
; http://php.net/max-input-nesting-level
;max_input_nesting_level = 64
; How many GET/POST/COOKIE input variables may be accepted
; max_input_vars = 1000
; Maximum amount of memory a script may consume (128MB)
; http://php.net/memory-limit
memory_limit = 128M

3
php.ini-production

@ -457,6 +457,9 @@ max_input_time = 60
; http://php.net/max-input-nesting-level
;max_input_nesting_level = 64
; How many GET/POST/COOKIE input variables may be accepted
; max_input_vars = 1000
; Maximum amount of memory a script may consume (128MB)
; http://php.net/memory-limit
memory_limit = 128M

Loading…
Cancel
Save