note 71078 added to function.mysql-connect

From: Date: Fri, 10 Nov 2006 21:43:37 +0000
Subject: note 71078 added to function.mysql-connect
Groups: php.notes 
Request: Send a blank email to php-notes+get-119596@lists.php.net to get a copy of this message
The addition of entries to httpd.conf to stop .inc files being served by Apache is certainly useful and to be recommended. But it doesn't change the fact that these files have to be readable by Apache so that the PHP processor can get at them. As long as your don't have multiple, possibly untrusted, users on your machine then that's OK. But when you are running a large multi-user service with thousands of users its always possible that one of them will look at your .inc files and take a note of the passwords you have in them. They could even copy them into their own scripts and modify your databases! Even if local users are trusted, there is always the possibility of a rogue script (PHP or some nastier language) being installed by an ignorant user. That script might then read your .inc files (whether or not they are in the web publishing tree) and expose your password. ---- Server IP: 66.163.161.117 Probable Submitter: 217.155.67.156 ---- Manual Page -- http://www.php.net/manual/en/function.mysql-connect.php Edit -- https://master.php.net/note/edit/71078 Del: integrated -- https://master.php.net/note/delete/71078/integrated Del: useless -- https://master.php.net/note/delete/71078/useless Del: bad code -- https://master.php.net/note/delete/71078/bad+code Del: spam -- https://master.php.net/note/delete/71078/spam Del: non-english -- https://master.php.net/note/delete/71078/non-english Del: in docs -- https://master.php.net/note/delete/71078/in+docs Del: other reasons-- https://master.php.net/note/delete/71078 Reject -- https://master.php.net/note/reject/71078 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#119596) next »