{"id":29886,"date":"2021-01-17T18:47:34","date_gmt":"2021-01-17T10:47:34","guid":{"rendered":"https:\/\/web.mwwsb.com.my\/pjci\/?post_type=kb&#038;p=29886"},"modified":"2023-01-18T11:52:18","modified_gmt":"2023-01-18T03:52:18","slug":"security-update-secure-and-update-your-php","status":"publish","type":"kb","link":"https:\/\/www.casbay.com\/guide\/kb\/security-update-secure-and-update-your-php","title":{"rendered":"SECURITY UPDATE: Secure and Update your PHP"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"29886\" class=\"elementor elementor-29886\" data-elementor-post-type=\"kb\">\n\t\t\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a14effe elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a14effe\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-20ea66c\" data-id=\"20ea66c\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-bb914bb elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"bb914bb\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6d16cdc\" data-id=\"6d16cdc\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e90d110 elementor-widget elementor-widget-heading\" data-id=\"e90d110\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">SECURITY UPDATE: Secure and Update your PHP<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2d277d0 elementor-widget elementor-widget-text-editor\" data-id=\"2d277d0\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>It is extremely important to secure your PHP and to keep your PHP version up to date in order to minimize security vulnerability. Therefore, here are the security enhancements we recommend you to apply: <\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eacd317 elementor-widget elementor-widget-heading\" data-id=\"eacd317\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">1) Install and configure ModSecurity<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cbf13fa elementor-widget elementor-widget-text-editor\" data-id=\"cbf13fa\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>ModSecurity is an open source for web applications intrusion detection \/ prevention engine. In other words, as an Apache Web server module, the purpose of ModSecurity is to increase web application security and protect web applications from known and unknown attacks.<\/p><p>Step of installation for ModSecurity:<br \/><strong>1) Firstly, Download yum repo and install the ModSecurity using yum.<\/strong><br \/><code>#wget -q -O \u2013| sh<\/code><br \/><code>#yum install mod_security<\/code><\/p><p><strong>2) Then, Download apply the ModSecurity rules.<\/strong><br \/><code>#cd\/etc\/httpd\/modsecurity.d &amp;&amp; wget<br \/>#tar \u2013xvvzf modsec-2.5-free-latest.tar.gz<\/code><\/p><p><strong>3) Next, Remove unwanted rules. <\/strong><br \/><code>#cd\/etc\/httpd\/modsecurity.d &amp;&amp; rm -Rf 00_asl_rbl.conf 00_asl_whitelist.conf<\/code><\/p><p><strong>4) Lastly, Restart apache service.<\/strong><br \/><code>#\/etc\/init.d\/httpd restart<\/code><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-229daa0 elementor-widget elementor-widget-heading\" data-id=\"229daa0\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">2) Install PHP HardenedPHP patch<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2cbfe8f elementor-widget elementor-widget-text-editor\" data-id=\"2cbfe8f\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The hardenedPHP patch is a patch that adds security hardening features to PHP to protect your servers from a number of well-known issues in PHP applications. It also safeguards the servers from potential unknown vulnerabilities within those applications or the PHP core itself.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-87eb32f elementor-widget elementor-widget-heading\" data-id=\"87eb32f\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">3) Keep your Plesk version and application version up to date<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f3995bb elementor-widget elementor-widget-text-editor\" data-id=\"f3995bb\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>** NOTE: mod_security and Suhosin were not fully tested with Plesk Sitebuilder. Therefore, if you are using Plesk Sitebuilder, it is recommended to disable mod_security and Suhosin on the publishing server.<\/p><p>Installation steps for Suhosin:<br \/><strong>1) Firstly, Download suhosin and install it.<\/strong><br \/><code>#cd\/usr\/local\/&lt;\/code?<br \/>\n<code>#wget<\/code><br \/><code>#tar-zxvf suhosin-0.9.18.tgz<\/code><br \/><code>#cd suhosin-0.9.18<\/code><br \/><code>#phpize<\/code><br \/><code>#.\/configure<\/code><br \/><code>#make &amp;&amp; make install<\/code><\/code><\/p><p><strong>2) Secondly, Add a load directive to php.ini.<\/strong><br \/><code>#extension=suhosin.so<\/code><\/p><p><strong>3) Then, Restart apache service.<\/strong><br \/><code>#\/etc\/init.d\/httpd restart<\/code><\/p><p><strong>&lt;&lt; PLESK Users &gt;&gt;<\/strong><\/p><p>Mod_security and Suhosin were not fully tested with Plesk Sitebuilder. In addition, if you are using Plesk Sitebuilder, it is recommended to disable mod_security and Suhosin on the publishing server.<\/p><p><strong>&lt;&lt; CPANEL\/WHM Users &gt;&gt;<\/strong><\/p><p>For server pre-installed with cPanel, you will only need to enable the ModSecurity module and Suhosin module from the EasyApache and recompile the Apache.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eccdac2 elementor-widget elementor-widget-text-editor\" data-id=\"eccdac2\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Interested in learning more regarding this topic? Well, you can browse through our <em><a href=\"https:\/\/www.casbay.com\/guide\/kb\/how-to-change-the-listening-port-for-remote-desktop\">Knowledge Base<\/a><\/em> to find some other similar articles.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>SECURITY UPDATE: Secure and Update your PHP It is extremely important to secure your PHP and to keep your PHP version up to date in order to minimize security vulnerability. Therefore, here are the security enhancements we recommend you to apply: 1) Install and configure ModSecurity ModSecurity is an open source for web applications intrusion [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"site-sidebar-layout":"no-sidebar","site-content-layout":"page-builder","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"disabled","ast-breadcrumbs-content":"","ast-featured-img":"disabled","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}}},"kbtopic":[113],"kbtag":[106],"mkb_version":[],"_links":{"self":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/29886"}],"collection":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/comments?post=29886"}],"version-history":[{"count":2,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/29886\/revisions"}],"predecessor-version":[{"id":38220,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/29886\/revisions\/38220"}],"wp:attachment":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/media?parent=29886"}],"wp:term":[{"taxonomy":"kbtopic","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kbtopic?post=29886"},{"taxonomy":"kbtag","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kbtag?post=29886"},{"taxonomy":"mkb_version","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/mkb_version?post=29886"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}