Set stricter PHP settings to secure joomla and wordpress installations

If you run a Joomla or WordPress installation with mod_php, the following settings in the vhost configuration file or the "Apache directives" field in ISPConfig can be used to set a stricter security policy. This helps limit the impact of a possible hack to this website and protect the other sites on the server. php_admin_value

I changed some directives in the virtual hosts by hand, but they suddenly disappeared.

Never edit the vhost file manually. On the next update of the system your changes will be overwritten! Instead put your additional vhost configuration in the Apache Directives field in the ISPConfig Interface. If you want to add something manually to other files, e.g Postfix' local-host-names, you can put your configuration at the end of

Some services are shown as “Offline” in the ISPConfig system monitor though they are running on the server.

ISPConfig checks the status of the services on localhost (IP: It may be that some of your services only allow connections to specific IP addresses and not (in Apache this is done with the Listen directive). If you allow connections to localhost the status will be shown correctly in the ISPConfig. Another possibility