way to protect .php file
| From: | Kittiwat Manosuthi | Date: | Thu, 17 May 2001 05:08:29 +0000 |
| Subject: | way to protect .php file | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-53160@lists.php.net to get a copy of this message | ||
In a virtual hosting environment, even though a directory permission is
set to 751, but you still need to leave world-readable permission on
individual php file that is to be read from a browser. In a scenario
where there's another user in the same server who can guess (or even
get, from URL) the name of php files, he can simply: cd
/home/user1/html; more thatfile.php. If thatfile.php contains
username/pwd to a db, this can lead to a compromise on that db.
Moreover, many times that db name is the same as username, as well as db
pwd is the same as user password!
Is there anyway one can protect this?
Thanks
-kittiwat