--- php.ini-dist.orig Fri Dec 30 18:19:43 2005 +++ php.ini-dist Mon Oct 16 08:12:28 2006 @@ -155,6 +155,15 @@ ; Safe Mode ; +; SECURITY NOTE: The FreeBSD Security Officer strongly recommend that +; the PHP Safe Mode feature not be relied upon for security, since the +; issues Safe Mode tries to handle cannot properly be handled in PHP +; (primarily due to PHP's use of external libraries). While many bugs +; in Safe Mode has been fixed it's very likely that more issues exist +; which allows a user to bypass Safe Mode restrictions. +; For increased security we always recommend to install the Suhosin +; extension. +; safe_mode = Off ; By default, Safe Mode does a UID compare check when