way to protect .php file

From: Date: Thu, 17 May 2001 05:08:29 +0000
Subject: way to protect .php file
Groups: php.general 
Request: Send a blank email to php-general+get-53160@lists.php.net to get a copy of this message
In a virtual hosting environment, even though a directory permission is set to 751, but you still need to leave world-readable permission on individual php file that is to be read from a browser. In a scenario where there's another user in the same server who can guess (or even get, from URL) the name of php files, he can simply: cd /home/user1/html; more thatfile.php. If thatfile.php contains username/pwd to a db, this can lead to a compromise on that db. Moreover, many times that db name is the same as username, as well as db pwd is the same as user password! Is there anyway one can protect this? Thanks -kittiwat

« previous php.general (#53160) next »