Re: Bad Practices
| From: | Rick Hodger | Date: | Wed, 14 Feb 2001 08:51:11 +0000 |
| Subject: | Re: Bad Practices | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-39599@lists.php.net to get a copy of this message | ||
"Jeff Oien" <jeff@webdesigns1.com> wrote in message
news:NDBBJKNCILKDCEGAJBAOAEADDDAA.jeff@webdesigns1.com...
> Would people like to list bad practices and also point us
> newbies to any articles online dealing with syntax, correct
> use of single and double quotes etc.?
People who create scripts that include a need for access to a SQL database,
meaning you need to give it a username and password then making the damn
configuration file be called something stupid like config.inc.
When you are scripting, using anything with a .inc extension is just asking
for trouble. If someone requests that file, it'll get passed straight to
them. It's a .inc, which means that PHP does not know to parse it. Which
means, that person can see your usernames and passwords. And because it's a
public package, they're far more likely to know the path to said file.
--
Rick Hodger