note 56407 added to security.filesystem

From: Date: Thu, 01 Sep 2005 16:50:54 +0000
Subject: note 56407 added to security.filesystem
Groups: php.notes 
Request: Send a blank email to php-notes+get-94613@lists.php.net to get a copy of this message
I keep application configuration files in the document root. I found the most effective trick to prevent access to them is to 1. Give them no code that actually runs when included (except for variable assignments), 2. Don't use register globals so nobody can do anything weird, 3. Name them *.php so PHP runs them when asked for 4. Don't have anything before <?php 5. Don't have a ?> ---- Manual Page -- http://www.php.net/manual/en/security.filesystem.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+56407 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes&reason=useless Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes&reason=non-english Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+56407&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#94613) next »