note 20221 modified in function.mysql-connect by philip

From: Date: Fri, 24 May 2002 15:26:25 +0000
Subject: note 20221 modified in function.mysql-connect by philip
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-30991@lists.php.net to get a copy of this message
There should already be a post in here about this, but I would like to follow up on the idea that anyone can read your .inc files, which might contain username/password combos for mysql access. There is a very simple way to block this. If you are using Apache, just edit your httpd.conf file, and look for the following lines: <Files ~ "^\.ht"> Order allow,deny Deny from all Satisfy All </Files> Okay... that little chunk of text is saying that you don't want files that begin with .ht to be readable through apache. We also don't want people to see any files that end with .inc. So, just add the following chunk of text to your httpd.conf file: <Files ~ ".inc"> Order allow,deny Deny from all Satisfy All </Files> This will block anyone from seeing your .inc files over the web. It is much smarter than naming include files, "*.php". Use the .php extension for your code, and save .inc for actual include data, and don't worry about people reading your .inc's anymore. Hope this helps somebody. Oh yeah... one other thing... obviously, anytime you make a change to httpd.conf (or whatever you have named your Apache config file), you must restart apache for the changes to take effect. --was-- There should already be a post in here about this, but I would like to follow up on the idea that anyone can read your .inc files, which might contain username/password combos for mysql access. There is a very simple way to block this. If you are using Apache, just edit your httpd.conf file, and look for the following lines: <Files ~ "^\.ht"> Order allow,deny Deny from all Satisfy All </Files> Okay... that little chunk of text is saying that you don't want files that begin with .ht to be readable through apache. We also don't want people to see any files that end with .inc. So, just add the following chunk of text to your httpd.conf file: <Files ~ ".inc"> Order allow,deny Deny from all Satisfy All </Files> This will block anyone from seeing your .inc files over the web. It is much smarter than naming include files, "*.php". Use the .php extension for your code, and save .inc for actual include data, and don't worry about people reading your .inc's anymore. Hope this helps somebody. Oh yeah... one other thing... obviously, anytime you make a change to httpd.conf (or whatever you have named your Apache config file), you must restart apache for the changes to take effect. Good luck!! :) - Dave www.code24.com http://www.php.net/manual/en/function.mysql-connect.php

« previous php.notes (#30991) next »