note 42516 added to security.globals

From: Date: Wed, 19 May 2004 16:06:19 +0000
Subject: note 42516 added to security.globals
Groups: php.notes 
Request: Send a blank email to php-notes+get-69837@lists.php.net to get a copy of this message
If you're under an Apache environment that has this option enabled, but you're on shared hosting so have no access to php.ini, you can unset this value for your own site by placing the following in an .htaccess file in the root: php_flag register_globals 0 The ini_set() function actually accomplishes nothing here, since the variables will have already been created by the time the script processes the ini file change. And since this is the security chapter, just as a side note, another thing that's helpful to put into your .htaccess is: <Files ".ht*"> deny from all </Files> That way no one can load .htaccess in their browser and have a peek at its contents. Sorry, not aware of a similar workaround for IIS. :\ ---- Manual Page -- http://www.php.net/manual/en/security.globals.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+42516 Delete -- http://master.php.net/manage/user-notes.php?action=delete+42516&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+42516&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#69837) next »