note 20221 modified in function.mysql-connect by philip
| From: | philip@php.net | Date: | Fri, 24 May 2002 15:26:25 +0000 |
| Subject: | note 20221 modified in function.mysql-connect by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-30991@lists.php.net to get a copy of this message | ||
There should already be a post in here about this, but I would like to follow up on the idea that
anyone can read your .inc files, which might contain username/password combos for mysql access.
There is a very simple way to block this.
If you are using Apache, just edit your httpd.conf file, and look for the following lines:
<Files ~ "^\.ht">
Order allow,deny
Deny from all
Satisfy All
</Files>
Okay... that little chunk of text is saying that you don't want files that begin with .ht to be
readable through apache. We also don't want people to see any files that end with .inc.
So, just add the following chunk of text to your httpd.conf file:
<Files ~ ".inc">
Order allow,deny
Deny from all
Satisfy All
</Files>
This will block anyone from seeing your .inc files over the web. It is much smarter than naming
include files, "*.php". Use the .php extension for your code, and save .inc for actual
include data, and don't worry about people reading your .inc's anymore.
Hope this helps somebody. Oh yeah... one other thing... obviously, anytime you make a change to
httpd.conf (or whatever you have named your Apache config file), you must restart apache for the
changes to take effect.
--was--
There should already be a post in here about this, but I would like to follow up on the idea that
anyone can read your .inc files, which might contain username/password combos for mysql access.
There is a very simple way to block this.
If you are using Apache, just edit your httpd.conf file, and look for the following lines:
<Files ~ "^\.ht">
Order allow,deny
Deny from all
Satisfy All
</Files>
Okay... that little chunk of text is saying that you don't want files that begin with .ht to be
readable through apache. We also don't want people to see any files that end with .inc.
So, just add the following chunk of text to your httpd.conf file:
<Files ~ ".inc">
Order allow,deny
Deny from all
Satisfy All
</Files>
This will block anyone from seeing your .inc files over the web. It is much smarter than naming
include files, "*.php". Use the .php extension for your code, and save .inc for actual
include data, and don't worry about people reading your .inc's anymore.
Hope this helps somebody. Oh yeah... one other thing... obviously, anytime you make a change to
httpd.conf (or whatever you have named your Apache config file), you must restart apache for the
changes to take effect.
Good luck!! :)
- Dave
www.code24.com
http://www.php.net/manual/en/function.mysql-connect.php