Re: Thread Reading
| From: | Jedi/Sector One | Date: | Thu, 19 Sep 2002 18:02:22 +0000 |
| Subject: | Re: Thread Reading | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-88472@lists.php.net to get a copy of this message | ||
On Thu, Sep 19, 2002 at 01:56:03PM -0400, devon@sitetronics.com wrote:
> This is a security standard that is already inherent in the current phps
> version. It is also not the job of PHP to save people from themselves.
And sensitive cleartext data like SQL passwords can always be passed
through environment variables. For instance, Apache has the 'Setenv'
directive to set this, and the httpd.conf file can be made only readable by
root.
That way, publishing the source code doesn't reveal anything.
--
__ /*- Frank DENIS (Jedi/Sector One) <j@42-Networks.Com> -*\ __
\ '/ <a href="http://www.PureFTPd.Org/"> Secure FTP Server
</a> \' /
\/ <a href="http://www.Jedi.Claranet.Fr/"> Misc. free
software </a> \/