Re: Bad Practices

From: Date: Wed, 14 Feb 2001 21:23:18 +0000
Subject: Re: Bad Practices
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-39745@lists.php.net to get a copy of this message
I told Apache to deny all .inc requets, ala .htaccess-style stuff in the httpd.conf -Szii ----- Original Message ----- From: Sebastian Stadtlich <Stadtlich@mediaworx.com> To: 'Rick Hodger' <rick@domainsbuy.com>; 'Php-General (E-Mail) <php-general@lists.php.net> Sent: Wednesday, February 14, 2001 4:45 AM Subject: AW: [PHP] Bad Practices > OR you could tell apache to parse everything that ends with .inc with php. > you can name it .inc .linux .linuxsucks .microsoftsucks > > (you'll need to have access to http.conf or .htaccess+right to override ...) > > sebastian > > > -----Ursprüngliche Nachricht----- > > Von: Rick Hodger [mailto:rick@domainsbuy.com] > > Gesendet: Mittwoch, 14. Februar 2001 09:51 > > An: php-general@lists.php.net > > Betreff: Re: [PHP] Bad Practices > > > > > > > > "Jeff Oien" <jeff@webdesigns1.com> wrote in message > > news:NDBBJKNCILKDCEGAJBAOAEADDDAA.jeff@webdesigns1.com... > > > Would people like to list bad practices and also point us > > > newbies to any articles online dealing with syntax, correct > > > use of single and double quotes etc.? > > > > People who create scripts that include a need for access to a > > SQL database, > > meaning you need to give it a username and password then > > making the damn > > configuration file be called something stupid like config.inc. > > > > When you are scripting, using anything with a .inc extension > > is just asking > > for trouble. If someone requests that file, it'll get passed > > straight to > > them. It's a .inc, which means that PHP does not know to > > parse it. Which > > means, that person can see your usernames and passwords. And > > because it's a > > public package, they're far more likely to know the path to said file. > > > > -- > > Rick Hodger > > > > > > > > -- > > PHP General Mailing List (http://www.php.net/) > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > > For additional commands, e-mail: php-general-help@lists.php.net > > To contact the list administrators, e-mail: > > php-list-admin@lists.php.net > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#39745) next »