在 php.ini 中找到
disable_functions =
这一行,在其后面添加需要禁止的危险函数名,以英文逗号分隔
disable_functions = phpinfo, set_time_limit,system,exec,shell_exec,passthru,
proc_open,proc_close,proc_get_status,checkdnsrr,getmxrr,getservby">name,
getservbyport,syslog,popen,show_source,highlight_file,posix_ctermid,
posix_get_last_error,posix_getcwd,posix_getegid,posix_geteuid,posix_getgid,
posix_getgrgid,posix_getgrnam,posix_getgroups,posix_getlogin,posix_getpgid,
posix_getpgrp,posix_getpid,posix_getppid,posix_getpwnam,posix_getpwuid,
posix_getrlimit,posix_getsid,posix_getuid,posix_isatty,posix_kill,posix_mkfifo,
posix_setegid,posix_seteuid,posix_setgid,posix_setpgid,posix_setsid,
posix_setuid,posix_strerror,posix_times,posix_ttyname,posix_uname,dl,
socket_listen,socket_create,socket_bind,socket_accept,socket_connect,
stream_socket_server,stream_socket_accept,stream_socket_client,ftp_connect,
ftp_login,ftp_pasv,ftp_get,zlib.compress,gzopen,gzpassthru,gzcompress,
passthru,chroot,scandir,chgrp,chown,shell_exec,proc_open,proc_get_status,
ini_alter,ini_restore,dl,pfsockopen,openlog,syslog,readlink,symlink,
popepassthu,stream_socket_srver,scandir,chgrp,chown,shell_exec,proc_open,
proc_get_status,error_log,ini_alter,ini_set,ini_restore,dl,pfsockopen,
syslog,readlink,symlink,popen,stream_socket_server,putenv