note 31441 deleted from function.parse-ini-file by victor
| From: | victor@php.net | Date: | Sat, 19 Jun 2004 15:18:32 +0000 |
| Subject: | note 31441 deleted from function.parse-ini-file by victor | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-71354@lists.php.net to get a copy of this message | ||
Note Submitter: monkey@dysfunksion.co.uk
----
A simple way of increasing security for .ini files when circumstances require them to be sat in your
webroot (such as shared/limited-access hosting), is to prepend the following lines to your ini file.
; <?php /* Send Notification */ error_log('Unauthorised web access to *.ini file
(file:' . $_SERVER['SCRIPT_FILENAME'] . ')',1,$__EMAIL_ADDRESS__); ?>
; <?php /* Log error in file */ error_log('Unauthorised web access to *.ini file
(file:' . $_SERVER['SCRIPT_FILENAME'] . ')',3,$__ROOT_TO_LOGS__); ?>
; <?php exit("Unauthorised web access to *.ini file.\n\nPermission
Denied.\nTerminated."); ?>
;
; Rest of ini file below...
The second line may be removed should your host not allow logging. This will then notify you of any
problems so you can take action.
Dysfunktional Monkey