cPFence v4 public beta is here.

Explore v4
Enhance CP Tutorials

Recommended Disabled Functions on Your Enhance Server

Php Functions conceptual feature illustration

This guide will walk you through disabling potentially dangerous functions in your server’s php.ini settings.

Use an Enhance administrator account on your Ubuntu 22.04/24.04 cluster. These are global application defaults, so save the existing value and check which websites need exceptions before changing it.

Why Disable Certain PHP Functions?

PHP is a powerful scripting language, but some of its functions can pose significant security risks if not managed properly. Functions like exec, system, and shell_exec can allow an attacker to execute arbitrary commands on your server, leading to severe security breaches. Disabling functions your applications do not need can reduce their available capabilities. The PHP manual warns that this setting can be circumvented and is not sufficient protection for shared hosting by itself.

Steps to Edit the php.ini Configuration

Keep application updates, isolation and access controls in place too.

To disable these functions, follow the steps below:

1- Open Settings:
In the left sidebar of your Enhance control panel, navigate to Settings.

2- Select Service Settings:
Under Settings, click on Service settings.

3- Scroll to the Application Section:
Locate the Application section and find php.ini.

4- Add the Directive:
Click on Add directive to include a new directive in the php.ini settings.

5- Set the disable_functions Directive:
In the directive field, enter disable_functions.

For the value, select Text then paste the following list of functions in text field:

exec,system,passthru,shell_exec,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname,pcntl_exec,expect_popen

6- Save Your Changes:

After entering the directive , click Save to apply the changes.

According to Enhance’s application settings guide, these defaults apply across application servers and can be overridden per website. Test normal page loads, scheduled jobs, backups and updates on affected sites. If something stops working, restore the saved value or allow the required function only for the affected website, then check it again.

Bonus Tip: Check Shell-Escaping Functions Before Disabling Them

Our original tip also listed escapeshellarg and escapeshellcmd. These functions escape shell input; they do not execute commands. PHP documents escapeshellarg as a way to quote an individual argument, so disabling it is not a general security improvement. Be cautious if you have a WHMCS installation, as disabling these functions might cause warnings or errors. Roundcube upgrades can also need them; see our Roundcube upgrade guide.

If you’re using the Enhance control panel, you can easily override the default php.ini settings on a per-website basis. This allows you to keep these functions disabled globally while enabling them only for sites that require them, such as WHMCS.

Conclusion

Securing your server involves more than one setting. Choose restrictions that fit your applications, keep exceptions narrow, and check that essential tasks still work. For additional server protection and monitoring, try cPFence v4+, tailored for Enhance servers.

Try cPFence Free for One Month

Bring server protection and monitoring together with cPFence v4+ for Enhance on Ubuntu 22.04/24.04.

Start free trial
← Back to all articles
KEEP EXPLORING
All articles