RE: [PHP] location of scripts with DB passwords
| From: | Dan Joseph | Date: | Thu, 01 May 2003 20:51:10 +0000 |
| Subject: | RE: [PHP] location of scripts with DB passwords | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-146004@lists.php.net to get a copy of this message | ||
Dennis,
I am not the foremost authority on security, but it is NOT secure to put
them there. If its in the doc root, it can be had...
-Dan Joseph
> -----Original Message-----
> From: Dennis Gearon [mailto:gearond@cvc.net]
> Sent: Thursday, May 01, 2003 4:49 PM
> To: php-general@lists.php.net
> Subject: [PHP] location of scripts with DB passwords
>
>
> ------------------------------------------------
> PLEASE RESPOND VIA BOTH THE LIST AND cc'ing ME,
> thanks in advance.
> ------------------------------------------------
> I've got a hosting provider who is switching me to an Ensim run site.
>
> The previous one was monster controls.
>
> I have another site on another host that also uses Ensim.
>
> The new one going to Ensim can't seem to give me the true
> harddrive location of my root account so that I can put the DB
> passwords and classes files, etc, outside of the document root.
>
> He is suggesting that I put those in the cgi directory, which
> resolves to the document root location:
>
> http://www.thesite.tld/cgi-bin/
>
> He says this will be safe for those files. I wonder about this.
> What is the access capability of a browser to *.php files in a
> cgi directory?
>
> On my other Ensim powered site with a different host, he gave me
> the account directory no problem.
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>