activa Posted December 8, 2015 Report Posted December 8, 2015 a lot of host and providers disable the exec functions . like us we disable it even if we use a own vps just for billing . yesterday we have recieved a new plugin of backups done from naja7host for remote cloud backups . and we find that the backup use a native php class for backup rather than the exec function used in bleta core . the class used is located here https://github.com/ifsnop/mysqldump-php . we suggest to add this class in the core or use a semilar class tgo do the backup proccess . Quote
Cody Posted December 9, 2015 Report Posted December 9, 2015 I can't see this happening. We're talking about backing up a database. It's a critical process that should be executed as fast and as efficient as possible. Someone could create a plugin that uses this slow, and not very well written, library if they wanted to avoid using exec commands. But the penalty is not worth the gain in my opinion. Michael 1 Quote
activa Posted December 18, 2015 Author Report Posted December 18, 2015 i have tested it and tested it , it do the jobs as wanted . even if we host just the billing in our server . we prefer disable exec function and using a alternative way , like the one we have now . Quote
serge Posted December 19, 2015 Report Posted December 19, 2015 I do not see why you should afraid of allowing exec , it's maybe do have a sense in a shared server, but when you use container or VPS or cloudlinux...it will be like not allowing you ssh command on your own server...and why would you such restriction, you just need it like you need exec. Michael 1 Quote
activa Posted December 21, 2015 Author Report Posted December 21, 2015 if the script can be exploited someday , you will know why i will disable exec . it's a mesure to minimize he damage IF something happen . Quote
Paul Posted December 21, 2015 Report Posted December 21, 2015 if the script can be exploited someday , you will know why i will disable exec . it's a mesure to minimize he damage IF something happen . If there is a vulnerability, chances are it won't even need exec perms to be exploited. If it's a big concern, you'll want to use an alternative tool to back up your database. R1Soft works very well, and I would highly recommend it. It's also a good idea to run Blesta on a private server. Michael 1 Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.