#1
  1. No Profile Picture
    Junior Member
    Devshed Newbie (0 - 499 posts)

    Join Date
    Jul 2000
    Posts
    7
    Rep Power
    0
    I put my database variables in an include (.inc) file since I use them in several other scripts. These are variables like the mysql server name, database name and password, which I obviously don't want to share with the world, but if I enter the URL of the include file, they are displayed right in the browser. Are there permissions I can set on the file so that php can access it but a browser won't, or do the settings in Apache need to be changed? For the time being, I've removed the file, of course.
  2. #2
  3. No Profile Picture
    Apprentice Deity
    Devshed Loyal (3000 - 3499 posts)

    Join Date
    Jul 1999
    Location
    Niagara Falls (On the wrong side of the gorge)
    Posts
    3,237
    Rep Power
    19
    You should do two things.

    1) use AddType in htppd.conf to make .inc a php parsable extension.

    2) place the file below the document root so that it cannot be accessed by a web browser. (your files that include it will still be able to access it)

    You're on the right track by placing sensitive info outside the main document.
  4. #3
  5. Contributing User
    Devshed Novice (500 - 999 posts)

    Join Date
    Feb 2000
    Location
    Perth West Australia
    Posts
    757
    Rep Power
    15
    or rename it includedfile.php3 , it does not need to be called .inc

    ------------------
    Simon Wheeler
    FirePages -DHTML/PHP/MySQL
  6. #4
  7. No Profile Picture
    Junior Member
    Devshed Newbie (0 - 499 posts)

    Join Date
    Jul 2000
    Posts
    7
    Rep Power
    0
    Thanks, both of you. I will try moving the file below the public folder, and renaming it with a .php extension. Because it's running on someone else's server, I can't change the Apache settings myself, so it'll take a little while to get that fixed.

Similar Threads

  1. Can't move or delete it!
    By Hykinsel007 in forum Windows Help
    Replies: 3
    Last Post: June 15th, 2004, 04:41 PM
  2. Reading files that has certain parrent at once
    By cgi_pro in forum Perl Programming
    Replies: 2
    Last Post: January 29th, 2004, 11:13 PM
  3. how to rename files
    By dxgn in forum Perl Programming
    Replies: 1
    Last Post: January 1st, 2004, 02:10 PM
  4. How can I pack servlet files into a jar file?
    By suryahema in forum Java Help
    Replies: 1
    Last Post: December 18th, 2003, 09:32 AM
  5. php protect files question
    By brainfuelmedia in forum PHP Development
    Replies: 2
    Last Post: November 1st, 2003, 01:34 AM

IMN logo majestic logo threadwatch logo seochat tools logo