Re: Thread Reading
| From: | Zeev Suraski | Date: | Thu, 19 Sep 2002 18:10:41 +0000 |
| Subject: | Re: Thread Reading | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-88475@lists.php.net to get a copy of this message | ||
At 20:10 19/09/2002, Adam Voigt wrote:
Newbie's or people seeking help with bad security standards, could give away the password to there SQL server, etc. Maybe the phps parser or whatever it's called should automatically *** out the password fields of all the db, ftp, etc. calls.I don't think that this argument holds too much water. You have to intentionally create .phps symlinks in order for them to be exposed. It's not any different from being able to create a .txt symlink to it. Anything else? Zeev