Re: Bad Practices

From: Date: Wed, 14 Feb 2001 17:30:27 +0000
Subject: Re: Bad Practices
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-39684@lists.php.net to get a copy of this message
Which is why anyone with a clue makes any special extensions they use protected by the web server. Which is why I protect .inc, .cfg, .class, etc. It's also a good idea not to store config-type files in the web tree. Rick Hodger wrote:
"Jeff Oien" <jeff@webdesigns1.com> wrote in message news:NDBBJKNCILKDCEGAJBAOAEADDDAA.jeff@webdesigns1.com...
Would people like to list bad practices and also point us newbies to any articles online dealing with syntax, correct use of single and double quotes etc.?
People who create scripts that include a need for access to a SQL database, meaning you need to give it a username and password then making the damn configuration file be called something stupid like config.inc. When you are scripting, using anything with a .inc extension is just asking for trouble. If someone requests that file, it'll get passed straight to them. It's a .inc, which means that PHP does not know to parse it. Which means, that person can see your usernames and passwords. And because it's a public package, they're far more likely to know the path to said file. -- Rick Hodger


« previous php.general (#39684) next »