Re: Bad Practices
| From: | szii@sziisoft.com | Date: | Wed, 14 Feb 2001 21:23:18 +0000 |
| Subject: | Re: Bad Practices | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-39745@lists.php.net to get a copy of this message | ||
I told Apache to deny all .inc requets, ala .htaccess-style stuff in
the httpd.conf
-Szii
----- Original Message -----
From: Sebastian Stadtlich <Stadtlich@mediaworx.com>
To: 'Rick Hodger' <rick@domainsbuy.com>; 'Php-General (E-Mail)
<php-general@lists.php.net>
Sent: Wednesday, February 14, 2001 4:45 AM
Subject: AW: [PHP] Bad Practices
> OR you could tell apache to parse everything that ends with .inc with php.
> you can name it .inc .linux .linuxsucks .microsoftsucks
>
> (you'll need to have access to http.conf or .htaccess+right to override
...)
>
> sebastian
>
> > -----Ursprüngliche Nachricht-----
> > Von: Rick Hodger [mailto:rick@domainsbuy.com]
> > Gesendet: Mittwoch, 14. Februar 2001 09:51
> > An: php-general@lists.php.net
> > Betreff: Re: [PHP] Bad Practices
> >
> >
> >
> > "Jeff Oien" <jeff@webdesigns1.com> wrote in message
> > news:NDBBJKNCILKDCEGAJBAOAEADDDAA.jeff@webdesigns1.com...
> > > Would people like to list bad practices and also point us
> > > newbies to any articles online dealing with syntax, correct
> > > use of single and double quotes etc.?
> >
> > People who create scripts that include a need for access to a
> > SQL database,
> > meaning you need to give it a username and password then
> > making the damn
> > configuration file be called something stupid like config.inc.
> >
> > When you are scripting, using anything with a .inc extension
> > is just asking
> > for trouble. If someone requests that file, it'll get passed
> > straight to
> > them. It's a .inc, which means that PHP does not know to
> > parse it. Which
> > means, that person can see your usernames and passwords. And
> > because it's a
> > public package, they're far more likely to know the path to said file.
> >
> > --
> > Rick Hodger
> >
> >
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-general-help@lists.php.net
> > To contact the list administrators, e-mail:
> > php-list-admin@lists.php.net
> >
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net