RE: [PHP] location of scripts with DB passwords

From: Date: Thu, 01 May 2003 20:51:10 +0000
Subject: RE: [PHP] location of scripts with DB passwords
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-146004@lists.php.net to get a copy of this message
Dennis, I am not the foremost authority on security, but it is NOT secure to put them there. If its in the doc root, it can be had... -Dan Joseph > -----Original Message----- > From: Dennis Gearon [mailto:gearond@cvc.net] > Sent: Thursday, May 01, 2003 4:49 PM > To: php-general@lists.php.net > Subject: [PHP] location of scripts with DB passwords > > > ------------------------------------------------ > PLEASE RESPOND VIA BOTH THE LIST AND cc'ing ME, > thanks in advance. > ------------------------------------------------ > I've got a hosting provider who is switching me to an Ensim run site. > > The previous one was monster controls. > > I have another site on another host that also uses Ensim. > > The new one going to Ensim can't seem to give me the true > harddrive location of my root account so that I can put the DB > passwords and classes files, etc, outside of the document root. > > He is suggesting that I put those in the cgi directory, which > resolves to the document root location: > > http://www.thesite.tld/cgi-bin/ > > He says this will be safe for those files. I wonder about this. > What is the access capability of a browser to *.php files in a > cgi directory? > > On my other Ensim powered site with a different host, he gave me > the account directory no problem. > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php >

« previous php.general (#146004) next »