note 71078 added to function.mysql-connect
| From: | Graham_Rule at ed dot ac dot uk | Date: | Fri, 10 Nov 2006 21:43:37 +0000 |
| Subject: | note 71078 added to function.mysql-connect | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-119596@lists.php.net to get a copy of this message | ||
The addition of entries to httpd.conf to stop .inc files being served by Apache is certainly useful
and to be recommended.
But it doesn't change the fact that these files have to be readable by Apache so that the PHP
processor can get at them.
As long as your don't have multiple, possibly untrusted, users on your machine then that's
OK. But when you are running a large multi-user service with thousands of users its always possible
that one of them will look at your .inc files and take a note of the passwords you have in them.
They could even copy them into their own scripts and modify your databases!
Even if local users are trusted, there is always the possibility of a rogue script (PHP or some
nastier language) being installed by an ignorant user. That script might then read your .inc files
(whether or not they are in the web publishing tree) and expose your password.
----
Server IP: 66.163.161.117
Probable Submitter: 217.155.67.156
----
Manual Page -- http://www.php.net/manual/en/function.mysql-connect.php
Edit -- https://master.php.net/note/edit/71078
Del: integrated -- https://master.php.net/note/delete/71078/integrated
Del: useless -- https://master.php.net/note/delete/71078/useless
Del: bad code -- https://master.php.net/note/delete/71078/bad+code
Del: spam -- https://master.php.net/note/delete/71078/spam
Del: non-english -- https://master.php.net/note/delete/71078/non-english
Del: in docs -- https://master.php.net/note/delete/71078/in+docs
Del: other reasons-- https://master.php.net/note/delete/71078
Reject -- https://master.php.net/note/reject/71078
Search -- https://master.php.net/manage/user-notes.php