Secuirity issues?
| From: | Lauri Vain | Date: | Wed, 15 Nov 2000 19:46:01 +0000 |
| Subject: | Secuirity issues? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-25516@lists.php.net to get a copy of this message | ||
Hello,
What is a bad thing to miss (that could become a secuirity issue) while writing
some PHP/SQL code?
I figure that I shouldn't put my config.inc.php (containing SQL passes) files in
a publically readable dir because people could use include() to get the
password.
The fix? Putting config.inc.php files outside of the web tree? Using a .htaccess
file in the .in dir?
Will PHP execute the PHP/SQL code inserted in text boxes? I've heard it does,
will it be fixed when I use just the addslashes() or will I need to use
something more? How about the escapeshellcmd(), should I use this too?
Does anybody know more about writing "secure" PHP scripts?
Yours,
Lauri