Home > Article > Backend Development > How to close phpinfo() function in php
php method to turn off the phpinfo() function: first find and open the "php.ini" configuration file; then find the "disable_functions=" item in the configuration file, and add "phpinfo," after the "=" sign value, save the file; finally restart the WEB service.
The operating environment of this tutorial: windows7 system, PHP7.1 version, DELL G3 computer
I believe that students who have been exposed to PHP are aware of phpinfo( ) The most common usage of this function is that we use it to test whether the PHP environment is successfully built or to detect PHP-related environment information.
Generally we will not disable this function. Because of the powerful function of phpinfo() function, some sensitive information of the server is often easily leaked.
So some cloud host security platforms and security scanning devices will define this function as a dangerous function or treat it as a vulnerable file.
If we want to avoid security scanning problems, we can manually set the php.ini configuration file to disable this function.
Find the PHP installation directory and open the php.ini configuration file, as shown in the figure below
Use Notepad to open the php.ini file and search for keywords "disable_functions", as shown in the picture
Add the function phpinfo that needs to be disabled and save it, and restart the WEB service, such as APACHE, IIS, NGINX, as shown in the picture below
Test again after completion. If you want to disable other functions, you can also add them according to the above method.
Recommended learning: "PHP Video Tutorial"
The above is the detailed content of How to close phpinfo() function in php. For more information, please follow other related articles on the PHP Chinese website!