note 42516 deleted from security.globals by danbrown
| From: | danbrown@php.net | Date: | Thu, 15 Jan 2009 16:41:36 +0000 |
| Subject: | note 42516 deleted from security.globals by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-149282@lists.php.net to get a copy of this message | ||
Note Submitter: snarkles <anything at $myname dot net>
----
If you're under an Apache environment that has this option enabled, but you're on shared
hosting so have no access to php.ini, you can unset this value for your own site by placing the
following in an .htaccess file in the root:
php_flag register_globals 0
The ini_set() function actually accomplishes nothing here, since the variables will have already
been created by the time the script processes the ini file change.
And since this is the security chapter, just as a side note, another thing that's helpful to
put into your .htaccess is:
<Files ".ht*">
deny from all
</Files>
That way no one can load .htaccess in their browser and have a peek at its contents.
Sorry, not aware of a similar workaround for IIS. :\