Set up Nginx with PHP-FPM to serve PHP applications exclusively through Tor. First, configure your hidden service in torrc, then set up the web stack:
# Install PHP-FPM
apt install -y php-fpm php-mysql php-curl php-gd php-mbstring php-xml
# Nginx server block for PHP over Tor
# /etc/nginx/sites-available/onion-php
server {
listen 127.0.0.1:8080;
root /var/www/onion;
index index.php index.html;
server_tokens off;
access_log off;
error_log /dev/null;
location / {
try_files $uri $uri/ /index.php?$query_string;
}
location ~ \.php$ {
include fastcgi_params;
fastcgi_pass unix:/run/php/php-fpm.sock;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_param SERVER_NAME $host;
fastcgi_hide_header X-Powered-By;
}
# Block access to sensitive files
location ~ /\.(env|git|htaccess) { deny all; }
location ~ /(composer\.json|composer\.lock) { deny all; }
}The fastcgi_hide_header X-Powered-By directive prevents PHP from advertising its version. The deny rules block access to common sensitive files that should never be served publicly.