在 CentOS 上配置 PHP 安全,通常可以从 系统层面、PHP 本身、Web 服务、代码与运维 几个方面来做。下面是一套比较实用、可落地的方案(适用于 CentOS 7/8、PHP 7.x/8.x)。
nginx、apache)rootchown -R nginx:nginx /var/www/html
chmod -R 755 /var/www/html
systemctl disable telnet
systemctl stop telnet
getenforce
setenforce 1
如 Web 目录异常:
semanage fcontext -a -t httpd_sys_rw_content_t "/var/www/html(/.*)?"
restorecon -Rv /var/www/html
路径一般为:
/etc/php.ini
/etc/php.d/*.ini
disable_functions = exec,passthru,shell_exec,system,proc_open,popen,pcntl_exec,eval
如业务需要,可酌情放开
display_errors = Off
log_errors = On
error_log = /var/log/php_errors.log
open_basedir = /var/www/html:/tmp
allow_url_fopen = Off
allow_url_include = Off
file_uploads = On
upload_max_filesize = 8M
post_max_size = 8M
upload_tmp_dir = /tmp
session.cookie_secure = On
session.cookie_httponly = On
session.cookie_samesite = Lax
session.use_strict_mode = 1
location ~ \.php$ {
fastcgi_pass unix:/run/php-fpm/www.sock;
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
}
# 禁止访问敏感文件
location ~ /\. {
deny all;
}
location ~* /(config|vendor|storage)/ {
deny all;
}
<Files ".env">
Require all denied
</Files>
<Directory "/var/www/html">
Options -Indexes
AllowOverride All
</Directory>
编辑:
/etc/php-fpm.d/www.conf
user = nginx
group = nginx
listen.owner = nginx
listen.group = nginx
pm = dynamic
使用 不同站点不同 pool(推荐):
/etc/php-fpm.d/site1.conf
/etc/php-fpm.d/site2.conf
composer install --no-dev --optimize-autoloader
composer audit
.envconfig.phpvendor/.git//var/log/php_errors.log
ausearch -m avc
journalctl -u php-fpm
auditdinotifyyum update -y
如果你愿意,我可以:
你用的是哪种环境?