Zen Cart Logo
Forums / General Questions / Warning: ini_set() has been disabled for security reasons

Warning: ini_set() has been disabled for security reasons

Locked

Views: 15,638

Results 1 to 4 of 4
This thread is locked. New replies are disabled.
5 Mar 2009, 1:33 PM
#1
flash avatar

flash

New Zenner

Join Date:
Mar 2004
Location:
Fort Collins, CO :: Play Hockey eh?!
Posts:
60
Plugin Contributions:
0

Warning: ini_set() has been disabled for security reasons

Viewing a completed order in admin. Adding comments, changing status to Delivered, with Append Comments and Notify Customer checked, then clicking the Update button gives:```
Warning: ini_set() has been disabled for security reasons in /home/awakened/public_html/secureshop/includes/classes/class.phpmailer.php on line 447

Warning: ini_set() has been disabled for security reasons in /home/awakened/public_html/secureshop/includes/classes/class.phpmailer.php on line 456

Warning: Cannot modify header information - headers already sent by (output started at /home/awakened/public_html/secureshop/includes/classes/class.phpmailer.php:447) in /home/awakened/public_html/secureshop/admin/includes/functions/general.php on line 21


Zen Cart 1.3.8a
Database Patch Level: 1.3.8

Server OS: Linux 2.6.18-028stab059.6
HTTP Server: Apache/1.3.41 (Unix) mod_log_bytes/1.2 mod_bwlimited/1.4 mod_ssl/2.8.31 OpenSSL/0.9.7a
PHP Version: 5.2.8 (Zend: 2.2.0)   PHP Memory Limit: 64M
PHP Core disable_functions: 
(local value)	show_source, passthru, popen, proc_open,ini_set	
(master value) show_source, passthru, popen, proc_open,ini_set

Flash

Larry 'Flash' Alexander
FLASH HQ

5 Mar 2009, 1:51 PM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Warning: ini_set() has been disabled for security reasons

Sounds like you're with a hosting company that's slapping on security restrictions willy-nilly in a panic instead of properly securing the server.

You should NOT have to do this, but if your hosting company isn't willing to secure their server more efficiently you'll have to manually edit lines 447 and 456 of the class.phpmailer.php file and add an @ symbol in front of the ini_set() function call on both lines to cause PHP to ignore the error.
That doesn't really solve anything other than suppressing the display of the error message. The problem will still exist, and you may actually have trouble getting the emails to go through due to the break in functionality caused by the PHP restrictions imposed by your host.

I would expect that all emails from your store are equally affected, both admin and storefront.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

5 Mar 2009, 2:27 PM
#3
flash avatar

flash

New Zenner

Join Date:
Mar 2004
Location:
Fort Collins, CO :: Play Hockey eh?!
Posts:
60
Plugin Contributions:
0

Re: Warning: ini_set() has been disabled for security reasons

Problem solved, thanks!

I've contacted my host.

Flash

Larry 'Flash' Alexander
FLASH HQ

3 Mar 2010, 5:07 PM
#4
fireflyfire avatar

fireflyfire

New Zenner

Join Date:
Mar 2010
Posts:
1
Plugin Contributions:
0

Re: Warning: ini_set() has been disabled for security reasons

We managed to solve this using PHP. (the client's hosting company was refusing to change server settings)

in class.phpmailer.php on line 446 447
change:
$old_from = ini_get("sendmail_from"); global $sendmail_from; $sendmail_from = ini_get("sendmail_from");
$sendmail_from = $this->Sender; //ini_set("sendmail_from", $this->Sender); $sendmail_from = $this->Sender;

line 455 456
change:
if($old_from) //if (isset($old_from))
$old_from = $sendmail_from;

in header_php.php line 400
change:
global $sendmail_from; //$sendmail_from = @ini_get("sendmail_from");