note 31082 deleted from function.parse-ini-file by didou

From: Date: Mon, 04 Aug 2003 17:10:57 +0000
Subject: note 31082 deleted from function.parse-ini-file by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-53330@lists.php.net to get a copy of this message
Note Submitter: tcn@pandora.be ---- Using ini files can be a security threat, if the visitor knows the filename, because ini files will just be readable like any other file, it is not parsed by the server. So, you should place any ini files outside your web root, where no deamons have access to. (For apache, outside the DocumentRoot) For example, Place your files in /var/www/ and your ini files in /var/settings/ or something. To read your ini files, just $IniFile=parse_ini_file ("/var/settings/my_site.ini"); Make sure it's properly CHMOD'ed!

« previous php.notes (#53330) next »