RE: [PHP] how to hide dbconnect file if its in publisheddirectory?
| From: | Navid A. Yar | Date: | Tue, 10 Jul 2001 05:01:49 +0000 |
| Subject: | RE: [PHP] how to hide dbconnect file if its in publisheddirectory? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-57065@lists.php.net to get a copy of this message | ||
Hmmm, I was wondering about security of PHP also. Does anyone know the
general issues of security within PHP documents? My thought is that PHP
cannot be seen when you view a source anyway, so isn't it secure enough
(besides the basic firewall and system security)?
-----Original Message-----
From: zerosumzero@yahoo.com [mailto:zerosumzero@yahoo.com]
Sent: Monday, July 09, 1979 11:40 PM
To: jweaver@erie.net; Rasmus Lerdorf
Cc: Noah Spitzer-Williams; php-general@lists.php.net
Subject: Re: [PHP] how to hide dbconnect file if its in
publisheddirectory?
on 7/10/01 12:30 AM, John Weaver at jww@jweaver.net wrote:
>
> Sorry, I should have been more clear. If you write modular code, your
> included file will be nothing but a group of functions. Call a file with
> nothing but functions in it and you get; <HTML><HEAD></HEAD></HTML>. I
can't
> see the security problem you refer to.
Ahhh!
I have this problem now ... do you put the <?php ?> tags on an inc file?
If not how do you keep people from reading it?
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net