note 114165 deleted from function.parse-ini-file by tularis
| From: | tularis@php.net | Date: | Sun, 19 Jan 2014 20:27:46 +0000 |
| Subject: | note 114165 deleted from function.parse-ini-file by tularis | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-198280@lists.php.net to get a copy of this message | ||
Note Submitter: Hasan
----
Trying to secure an .ini file by mixing it with PHP tags and comments (as below) is a _bad_ idea. If
the server is not also setup to parse .ini files as PHP then the entire content of .ini file will be
displayed.
; DON'T DO THAT, unless you told you web server to parse .ini files as PHP
;<?php
;die(); // For further security
;/*
[category]
name="value"
;*/
;?>