Results 1 to 4 of 4
  1. #1
    Join Date
    Mar 2004
    Location
    Finland
    Posts
    488
    Plugin Contributions
    3

    Default PHP safe mode ... what will it break?

    Hi all...

    I crafted a zencart store for a customer on my own developement server... when ready with the layout and settings, I installed zencart on the customers server only to notice that it has safe mode on!

    The hosting company has been asked to but safe mode off, but they refuse by saying it would lead to security issues!

    the problem is, that the customer doesn't want to change hosting company (not my place to argue) and does not want to get another hosting plan from somewhere else just for the shop...

    ...so I installed the zen cart, replaced the files I had edited and replaced the freshly installed database by the one from my dev. server... everything seems to be fine and everything seems to work...

    So the question is...

    What exactly does safe mode break!?
    Will it actually affect the shops behaviour somehow?
    Working with Zen Cart since 2003 :: www.prr.fi
    Author of the original Finnish language pack for Zen Cart since 2004

  2. #2
    Join Date
    Mar 2004
    Location
    Finland
    Posts
    488
    Plugin Contributions
    3

    Default Re: PHP safe mode ... what will it break?

    Anyone?

    This is quite urgent!
    Working with Zen Cart since 2003 :: www.prr.fi
    Author of the original Finnish language pack for Zen Cart since 2004

  3. #3
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: PHP safe mode ... what will it break?

    Among other things, Safe Mode may prevent the ability to use tools such as currency rate updates, database backups using the mysql-backup-plugin, timer-extensions on pages that are expected to take a long time to process, and in some cases the ability to upload product images. It may also cause unexpected and unpredictable error messages anywhere during the customers' shopping experience.

    Zen Cart is not designed to run on servers running PHP in safe mode. It is not regularly tested for safe-mode support, and there are no plans to aggressively handle such configuration. It is prudent to host your ecommerce business on a trustworthy, well-configured, non-overloaded server.

    In my observation, running a server in safe mode is only needed if the host doesn't have a good handle on security precautions and configurations, and/or has a lot of unscrupulous customers who leave their sites/accounts vulnerable to intrusion, causing the server to be open to hack attacks. The host has most likely been victim to several serious hack attempts and is now operating paranoid instead of efficiently. To run an ecommerce business on a server having those risks on it is not particularly wise. Most free-hosting accounts are served from servers running in php safe mode due to these same inherent risks in unmonitored and possibly questionable accountholders (and even just newbies who know little or nothing about websites and are just starting out but have a learning curve ahead), leaving security loopholes open in abundance.

    All you can do is let your customer know of the risks and let them make their decision. Hopefully they will research further and understand the benefit of finding a host that doesn't *need* to run their server in safe mode.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  4. #4
    Join Date
    Mar 2004
    Location
    Finland
    Posts
    488
    Plugin Contributions
    3

    Default Re: PHP safe mode ... what will it break?

    It is kind of funny, that the hosting package is quite expensive (for Finnish one atleast) and the company has otherwise good reputation...

    must be that they have incompetent system administrators who are unable to configure the server right!

    Thanks for the information, I will relay it to my customer and see what they think.
    Working with Zen Cart since 2003 :: www.prr.fi
    Author of the original Finnish language pack for Zen Cart since 2004

 

 

Similar Threads

  1. Server issue or what? running PHP in safe mode
    By lorhan in forum General Questions
    Replies: 6
    Last Post: 21 Dec 2006, 11:04 PM
  2. PHP Safe Mode
    By Caddy in forum Installing on a Windows Server
    Replies: 1
    Last Post: 13 Oct 2006, 09:49 AM
  3. Will safe mode make customer login impossible?
    By tiki in forum Installing on a Linux/Unix Server
    Replies: 19
    Last Post: 31 Jul 2006, 08:58 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR