note 56407 deleted from security.filesystem by sobak
| From: | sobak@php.net | Date: | Thu, 01 Dec 2016 12:38:39 +0000 |
| Subject: | note 56407 deleted from security.filesystem by sobak | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-207835@lists.php.net to get a copy of this message | ||
Note Submitter: joshudson';DROP TABLE EMAILS;' gmail.com
----
I keep application configuration files in the document root. I found the most effective trick to
prevent access to them is to
1. Give them no code that actually runs when included (except for variable assignments),
2. Don't use register globals so nobody can do anything weird,
3. Name them *.php so PHP runs them when asked for
4. Don't have anything before <?php
5. Don't have a ?>