location of scripts with DB passwords
| From: | Dennis Gearon | Date: | Thu, 01 May 2003 20:48:45 +0000 |
| Subject: | location of scripts with DB passwords | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-146003@lists.php.net to get a copy of this message | ||
------------------------------------------------
PLEASE RESPOND VIA BOTH THE LIST AND cc'ing ME, thanks in advance.
------------------------------------------------
I've got a hosting provider who is switching me to an Ensim run site.
The previous one was monster controls.
I have another site on another host that also uses Ensim.
The new one going to Ensim can't seem to give me the true harddrive location of my root account so that I can put the DB passwords and classes files, etc, outside of the document root.
He is suggesting that I put those in the cgi directory, which resolves to the document root location:
http://www.thesite.tld/cgi-bin/
He says this will be safe for those files. I wonder about this. What is the access capability of a browser to *.php files in a cgi directory?
On my other Ensim powered site with a different host, he gave me the account directory no problem.