Re: Security
| From: | Koos van den Hout | Date: | Thu, 21 Sep 2000 20:30:49 +0000 |
| Subject: | Re: Security | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-3039@lists.php.net to get a copy of this message | ||
Quoting Enrico Comini who wrote on Thu, Sep 21, 2000 at 10:19:24PM +0200:
> There are too INDEX.PHP3 and INDEX.HTML but if ONE see the file list and
> download the php files then He read my script with user name and password to
> connect my database and other information.
>
> How is possible to make the file in the site HIDDEN to prevent it ?
First check if it is possible to download the php3 files as-is (without
executing them). If that is possible, the webserver is misconfigured
anyway.
Then, maybe you can include the "secrets" from a directory outside your
webspace. If you use a good webserver setup, part of the files can be
outside the http root.
You also want to store result files and tempfiles outside your web root.
Koos van den Hout
--
Koos van den Hout, PGP keyid RSA/1024 0xCA845CB5 via keyservers
koos@kzdoos.xs4all.nl or DSS/1024 0xF0D7C263 -?)
Fax +31-30-2817051 Visit my site about books with reviews /\\
http://idefix.net/~koos/ http://www.virtualbookcase.com/ _\_V