


Comparison of three configuration methods of PHP under IIS, three configurations of iisphp_PHP tutorial
Comparison of the three configuration methods of PHP under IIS, three configurations of iisphp
When configuring PHP under Windows IIS 6.0, there are usually three configuration methods: CGI, ISAPI and FastCGI. This All three modes can run successfully under IIS 6.0. Now I will talk about the differences in configuration and performance of these three modes.
1. CGI (Common Gateway Interface) is generally an executable program, such as an EXE file, and the WEB server each occupies a different process, and generally a CGI program can only handle one user request. In this way, when the number of user requests is very large, it will occupy a large amount of system resources, such as memory, CPU time, etc., resulting in low performance.
2. ISAPI (Internet Server Application Program Interface) is a set of API interfaces for WEB services provided by Microsoft. It can realize all the functions provided by CGI, and has been extended on this basis, such as providing filter applications. program interface. ISAPI applications are mostly used in the form of DLL dynamic libraries, which can be executed after being requested by the user. They will not disappear immediately after processing a user request, but will continue to reside in the memory and wait for other user input to be processed. In addition, ISAPI's DLL application and WEB server are in the same process, and the efficiency is significantly higher than CGI.
Configure ISAPI PHP under IIS6 of Windows Server 2003. The configuration method is to add a new WEB service extension in the "WEB Service Extension" of IIS. The program suffix is PHP and the ISAPI program is php5isapi.dll. Then add the variable name PHPRC in "Environment Variables" - "System Variables", and the value is the path to php.ini. In the Internet Information Service Manager, select the root directory of the website or application, and open the directory property page (right-click and select " Properties") and then select "Home Directory". Click the "Configure" button and select the "Mapping" tab page. Click "Add...", set the "Executable File" to: c:phpphp5isapi.dll, set the extension to .php, select "Confirm whether the file exists", and then "OK" to save the settings. Restart the server to complete the PHP configuration.
3. FastCGI is an open extension of CGI with scalable architecture. Its main behavior is to keep the CGI interpreter process in memory and thus obtain higher performance. Repeated loading of traditional CGI interpreters is the main reason for low CGI performance. If the CGI interpreter remains in memory and accepts FastCGI process manager scheduling, it can provide good performance, scalability, etc.
FastCGI has been integrated into IIS7 and also supports IIS6. For the installation method in IIS6, please refer to Microsoft’s official documentation. I will briefly translate it here.
First click here to download a 32-bit FastCGI extension for IIS, and then install it. The installed file should be placed in the system32inetsrv directory.
Then open the system32inetsrv directory and execute the following statement, where c:php is your PHP directory and can be modified to other values.
cscript fcgiconfig.js -add -section:"PHP" -extension:php -path:"c:phpphp-cgi.exe"
In the Internet Information Services Manager, select the root directory of the website or application, open the directory property page (right-click and select "Properties"), and then select "Home Directory". Click the "Configure" button and select the "Mapping" tab page. Click "Add...", set the "Executable File" to: c:windowssystem32inetsrvfcgiext.dll, set the extension to .php, select "Confirm whether the file exists", and then "OK" to save the settings.
Modify the php.ini file and add the following statement:
fastcgi.impersonate = 1
cgi.fix_pathinfo = 1
cgi.force_redirect = 0
Then open the system32inetsrv directory and execute the following statement:
cscript fcgiconfig.js -set -section:"PHP" -InstanceMaxRequests:10000
cscript fcgiconfig.js -set -section:"PHP" -EnvironmentVars:PHP_FCGI_MAX_REQUESTS:10000
Finally, configure the security of the c:php directory so that the IIS_WPG group has read and execute permissions for this directory.
At this time, PHP based on FastCGI has been successfully configured on IIS6.

To protect the application from session-related XSS attacks, the following measures are required: 1. Set the HttpOnly and Secure flags to protect the session cookies. 2. Export codes for all user inputs. 3. Implement content security policy (CSP) to limit script sources. Through these policies, session-related XSS attacks can be effectively protected and user data can be ensured.

Methods to optimize PHP session performance include: 1. Delay session start, 2. Use database to store sessions, 3. Compress session data, 4. Manage session life cycle, and 5. Implement session sharing. These strategies can significantly improve the efficiency of applications in high concurrency environments.

Thesession.gc_maxlifetimesettinginPHPdeterminesthelifespanofsessiondata,setinseconds.1)It'sconfiguredinphp.iniorviaini_set().2)Abalanceisneededtoavoidperformanceissuesandunexpectedlogouts.3)PHP'sgarbagecollectionisprobabilistic,influencedbygc_probabi

In PHP, you can use the session_name() function to configure the session name. The specific steps are as follows: 1. Use the session_name() function to set the session name, such as session_name("my_session"). 2. After setting the session name, call session_start() to start the session. Configuring session names can avoid session data conflicts between multiple applications and enhance security, but pay attention to the uniqueness, security, length and setting timing of session names.

The session ID should be regenerated regularly at login, before sensitive operations, and every 30 minutes. 1. Regenerate the session ID when logging in to prevent session fixed attacks. 2. Regenerate before sensitive operations to improve safety. 3. Regular regeneration reduces long-term utilization risks, but the user experience needs to be weighed.

Setting session cookie parameters in PHP can be achieved through the session_set_cookie_params() function. 1) Use this function to set parameters, such as expiration time, path, domain name, security flag, etc.; 2) Call session_start() to make the parameters take effect; 3) Dynamically adjust parameters according to needs, such as user login status; 4) Pay attention to setting secure and httponly flags to improve security.

The main purpose of using sessions in PHP is to maintain the status of the user between different pages. 1) The session is started through the session_start() function, creating a unique session ID and storing it in the user cookie. 2) Session data is saved on the server, allowing data to be passed between different requests, such as login status and shopping cart content.

How to share a session between subdomains? Implemented by setting session cookies for common domain names. 1. Set the domain of the session cookie to .example.com on the server side. 2. Choose the appropriate session storage method, such as memory, database or distributed cache. 3. Pass the session ID through cookies, and the server retrieves and updates the session data based on the ID.


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

EditPlus Chinese cracked version
Small size, syntax highlighting, does not support code prompt function

ZendStudio 13.5.1 Mac
Powerful PHP integrated development environment

DVWA
Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is very vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, to help web developers better understand the process of securing web applications, and to help teachers/students teach/learn in a classroom environment Web application security. The goal of DVWA is to practice some of the most common web vulnerabilities through a simple and straightforward interface, with varying degrees of difficulty. Please note that this software

MantisBT
Mantis is an easy-to-deploy web-based defect tracking tool designed to aid in product defect tracking. It requires PHP, MySQL and a web server. Check out our demo and hosting services.

mPDF
mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),