note 56407 added to security.filesystem
| From: | joshudson | Date: | Thu, 01 Sep 2005 16:50:54 +0000 |
| Subject: | note 56407 added to security.filesystem | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-94613@lists.php.net to get a copy of this message | ||
I keep application configuration files in the document root. I found the most effective trick to
prevent access to them is to
1. Give them no code that actually runs when included (except for variable assignments),
2. Don't use register globals so nobody can do anything weird,
3. Name them *.php so PHP runs them when asked for
4. Don't have anything before <?php
5. Don't have a ?>
----
Manual Page -- http://www.php.net/manual/en/security.filesystem.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+56407
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes&reason=non-english
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+56407&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+56407&report=yes
Search -- http://master.php.net/manage/user-notes.php