note 31082 deleted from function.parse-ini-file by didou
| From: | didou@php.net | Date: | Mon, 04 Aug 2003 17:10:57 +0000 |
| Subject: | note 31082 deleted from function.parse-ini-file by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-53330@lists.php.net to get a copy of this message | ||
Note Submitter: tcn@pandora.be
----
Using ini files can be a security threat, if the visitor knows the filename, because ini files will
just be readable like any other file, it is not parsed by the server.
So, you should place any ini files outside your web root, where no deamons have access to. (For
apache, outside the DocumentRoot)
For example,
Place your files in /var/www/
and your ini files in /var/settings/
or something.
To read your ini files, just
$IniFile=parse_ini_file ("/var/settings/my_site.ini");
Make sure it's properly CHMOD'ed!