Re: Security

From: Date: Thu, 21 Sep 2000 20:30:49 +0000
Subject: Re: Security
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-3039@lists.php.net to get a copy of this message
Quoting Enrico Comini who wrote on Thu, Sep 21, 2000 at 10:19:24PM +0200: > There are too INDEX.PHP3 and INDEX.HTML but if ONE see the file list and > download the php files then He read my script with user name and password to > connect my database and other information. > > How is possible to make the file in the site HIDDEN to prevent it ? First check if it is possible to download the php3 files as-is (without executing them). If that is possible, the webserver is misconfigured anyway. Then, maybe you can include the "secrets" from a directory outside your webspace. If you use a good webserver setup, part of the files can be outside the http root. You also want to store result files and tempfiles outside your web root. Koos van den Hout -- Koos van den Hout, PGP keyid RSA/1024 0xCA845CB5 via keyservers koos@kzdoos.xs4all.nl or DSS/1024 0xF0D7C263 -?) Fax +31-30-2817051 Visit my site about books with reviews /\\ http://idefix.net/~koos/ http://www.virtualbookcase.com/ _\_V

« previous php.db (#3039) next »