dongshanjin8947 2017-07-28 09:28
浏览 100

PHP conf文件权限

Having this strtucture in a PHP proyect:

htdocs/
    project_name/
    conf/
        db_info.xml
    html/
        index.php

index.php is reading db_info.xml

The owner and group of this project is and user created for it.

DOCUMENT_ROOT is htdocs/project_name/html/

Is insecure to set 644 the file with the DB info and credentials (db_info.xml)?

Read permision for all could be a security issue or let folder named 'conf' out of the DOCUMENT_ROOT shouldn't be a problem?

  • 写回答

2条回答 默认 最新

  • dongshi6529 2017-07-28 09:33
    关注

    It depends on your web server configuration - if you don't allow the web server to read and serve the conf directory publicly - should not be a problem. But generaly you should consider moving the configs out of a public folder.

    评论

报告相同问题?

悬赏问题

  • ¥15 Centos7 / PETGEM
  • ¥15 csmar数据进行spss描述性统计分析
  • ¥15 各位请问平行检验趋势图这样要怎么调整?说标准差差异太大了
  • ¥15 delphi webbrowser组件网页下拉菜单自动选择问题
  • ¥15 wpf界面一直接收PLC给过来的信号,导致UI界面操作起来会卡顿
  • ¥15 init i2c:2 freq:100000[MAIXPY]: find ov2640[MAIXPY]: find ov sensor是main文件哪里有问题吗
  • ¥15 运动想象脑电信号数据集.vhdr
  • ¥15 三因素重复测量数据R语句编写,不存在交互作用
  • ¥15 微信会员卡等级和折扣规则
  • ¥15 微信公众平台自制会员卡可以通过收款码收款码收款进行自动积分吗