Disable PHP stack traces in Apache logs? The 2019 Stack Overflow Developer Survey Results Are InCompile PHP with Apache 2.4 handlerDisable Apache server signaturephp servers without apache/nginx/cgi stackBitnami apache + php-fpm stack can't disable bufferOpenBSD Nginx/PHP/MariaDB/PHP-FPM StackHow to disable PHP mail function on one apache virtualhost?Apache 2.4 unusual logsphp script from sh from crontab die with no tracesseparate php error logs for each Apache vhostsApache 2.4.7 ignores response header Content-Encoding: identity, instead respects Content-Encoding: none, set by PHP
What could be the right powersource for 15 seconds lifespan disposable giant chainsaw?
If Wish Duplicates Simulacrum, Are Existing Duplicates Destroyed?
Evaluating number of iteration with a certain map with While
Should I write numbers in words or as symbols in this case?
What is the use of option -o in the useradd command?
How to manage monthly salary
The difference between dialogue marks
Carnot-Caratheodory metric
I see my dog run
Is it possible for the two major parties in the UK to form a coalition with each other instead of a much smaller party?
Geography at the pixel level
What does "rabbited" mean/imply in this sentence?
What are the motivations for publishing new editions of an existing textbook, beyond new discoveries in a field?
Why Did Howard Stark Use All The Vibranium They Had On A Prototype Shield?
Is this food a bread or a loaf?
What is the best strategy for white in this position?
A poker game description that does not feel gimmicky
Lethal sonic weapons
Inflated grade on resume at previous job, might former employer tell new employer?
Is "plugging out" electronic devices an American expression?
Where to refill my bottle in India?
How can I create a character who can assume the widest possible range of creature sizes?
Fractional alignment
Why do UK politicians seemingly ignore opinion polls on Brexit?
Disable PHP stack traces in Apache logs?
The 2019 Stack Overflow Developer Survey Results Are InCompile PHP with Apache 2.4 handlerDisable Apache server signaturephp servers without apache/nginx/cgi stackBitnami apache + php-fpm stack can't disable bufferOpenBSD Nginx/PHP/MariaDB/PHP-FPM StackHow to disable PHP mail function on one apache virtualhost?Apache 2.4 unusual logsphp script from sh from crontab die with no tracesseparate php error logs for each Apache vhostsApache 2.4.7 ignores response header Content-Encoding: identity, instead respects Content-Encoding: none, set by PHP
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I've run across an in-house PHP application which occasionally crashes during user authentication and dumps a stacktrace into /var/log/apache2/. Problem is it logs the username and pass in cleartext.
PHP Fatal error...Stack trace:...ldapauthenticated('bobuser', 'secrit123')...
I've run across a few mentions on various stack* forums about disabling the stack traces in .htaccess or with a line of code in the PHP app itself however there seem to be varying degrees of success with these methods and I'd rather just disable the lot of it site-wide instead of editing a jazillion PHP code files.
I thought I'd poke around in /etc/php/ for an obvious setting somehow but there are myriad files and several directories there (7.0/ir, 7.0/cli, 7.0/cli/conf.d, 7.0/apache2/conf.d/,...) and no idea which file takes precedence over the other. I did find a log_errors setting which looked promising in 7.0/apache2/php.ini however the comment there says the default is off. Obviously either not working or the wrong config item.
Anyone know of a way to disable PHP stacktraces site wide?
php security apache-2.4
add a comment |
I've run across an in-house PHP application which occasionally crashes during user authentication and dumps a stacktrace into /var/log/apache2/. Problem is it logs the username and pass in cleartext.
PHP Fatal error...Stack trace:...ldapauthenticated('bobuser', 'secrit123')...
I've run across a few mentions on various stack* forums about disabling the stack traces in .htaccess or with a line of code in the PHP app itself however there seem to be varying degrees of success with these methods and I'd rather just disable the lot of it site-wide instead of editing a jazillion PHP code files.
I thought I'd poke around in /etc/php/ for an obvious setting somehow but there are myriad files and several directories there (7.0/ir, 7.0/cli, 7.0/cli/conf.d, 7.0/apache2/conf.d/,...) and no idea which file takes precedence over the other. I did find a log_errors setting which looked promising in 7.0/apache2/php.ini however the comment there says the default is off. Obviously either not working or the wrong config item.
Anyone know of a way to disable PHP stacktraces site wide?
php security apache-2.4
What Linux distribution is it? What PHP version? Where did you obtain it?
– Michael Hampton♦
Apr 5 at 16:59
Ubuntu 16.04 running bundled PHP 7.0 (not the ondrej repo)
– Server Fault
Apr 5 at 18:48
Your application also needs an exception handler to not die with a trace, at least when there is a credential on the stack.
– John Mahowald
Apr 6 at 11:37
add a comment |
I've run across an in-house PHP application which occasionally crashes during user authentication and dumps a stacktrace into /var/log/apache2/. Problem is it logs the username and pass in cleartext.
PHP Fatal error...Stack trace:...ldapauthenticated('bobuser', 'secrit123')...
I've run across a few mentions on various stack* forums about disabling the stack traces in .htaccess or with a line of code in the PHP app itself however there seem to be varying degrees of success with these methods and I'd rather just disable the lot of it site-wide instead of editing a jazillion PHP code files.
I thought I'd poke around in /etc/php/ for an obvious setting somehow but there are myriad files and several directories there (7.0/ir, 7.0/cli, 7.0/cli/conf.d, 7.0/apache2/conf.d/,...) and no idea which file takes precedence over the other. I did find a log_errors setting which looked promising in 7.0/apache2/php.ini however the comment there says the default is off. Obviously either not working or the wrong config item.
Anyone know of a way to disable PHP stacktraces site wide?
php security apache-2.4
I've run across an in-house PHP application which occasionally crashes during user authentication and dumps a stacktrace into /var/log/apache2/. Problem is it logs the username and pass in cleartext.
PHP Fatal error...Stack trace:...ldapauthenticated('bobuser', 'secrit123')...
I've run across a few mentions on various stack* forums about disabling the stack traces in .htaccess or with a line of code in the PHP app itself however there seem to be varying degrees of success with these methods and I'd rather just disable the lot of it site-wide instead of editing a jazillion PHP code files.
I thought I'd poke around in /etc/php/ for an obvious setting somehow but there are myriad files and several directories there (7.0/ir, 7.0/cli, 7.0/cli/conf.d, 7.0/apache2/conf.d/,...) and no idea which file takes precedence over the other. I did find a log_errors setting which looked promising in 7.0/apache2/php.ini however the comment there says the default is off. Obviously either not working or the wrong config item.
Anyone know of a way to disable PHP stacktraces site wide?
php security apache-2.4
php security apache-2.4
asked Apr 5 at 15:56
Server FaultServer Fault
1,73311638
1,73311638
What Linux distribution is it? What PHP version? Where did you obtain it?
– Michael Hampton♦
Apr 5 at 16:59
Ubuntu 16.04 running bundled PHP 7.0 (not the ondrej repo)
– Server Fault
Apr 5 at 18:48
Your application also needs an exception handler to not die with a trace, at least when there is a credential on the stack.
– John Mahowald
Apr 6 at 11:37
add a comment |
What Linux distribution is it? What PHP version? Where did you obtain it?
– Michael Hampton♦
Apr 5 at 16:59
Ubuntu 16.04 running bundled PHP 7.0 (not the ondrej repo)
– Server Fault
Apr 5 at 18:48
Your application also needs an exception handler to not die with a trace, at least when there is a credential on the stack.
– John Mahowald
Apr 6 at 11:37
What Linux distribution is it? What PHP version? Where did you obtain it?
– Michael Hampton♦
Apr 5 at 16:59
What Linux distribution is it? What PHP version? Where did you obtain it?
– Michael Hampton♦
Apr 5 at 16:59
Ubuntu 16.04 running bundled PHP 7.0 (not the ondrej repo)
– Server Fault
Apr 5 at 18:48
Ubuntu 16.04 running bundled PHP 7.0 (not the ondrej repo)
– Server Fault
Apr 5 at 18:48
Your application also needs an exception handler to not die with a trace, at least when there is a credential on the stack.
– John Mahowald
Apr 6 at 11:37
Your application also needs an exception handler to not die with a trace, at least when there is a credential on the stack.
– John Mahowald
Apr 6 at 11:37
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f961726%2fdisable-php-stack-traces-in-apache-logs%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f961726%2fdisable-php-stack-traces-in-apache-logs%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
What Linux distribution is it? What PHP version? Where did you obtain it?
– Michael Hampton♦
Apr 5 at 16:59
Ubuntu 16.04 running bundled PHP 7.0 (not the ondrej repo)
– Server Fault
Apr 5 at 18:48
Your application also needs an exception handler to not die with a trace, at least when there is a credential on the stack.
– John Mahowald
Apr 6 at 11:37