Menu

#2 include file exposure

v1.0_(example)
closed
nobody
5
2003-05-13
2002-08-27
Anonymous
No

the .INC files are a bad idea. You should instead
use .php for the config files.

If the web server is not set up probably, a hacker can
view your ftp user simply by view the comic_config.inc
file.

For the next version, I suggest you change it to .php so
hackers can not view the config files.

Discussion

  • Andres Baravalle

    Logged In: YES
    user_id=293285

    I agree that .inc can be problematic with a non-correct web
    server setup.
    Nevertheless, there are several common ways to protect this,
    and .inc is a very common choice for included files.
    .inc (or .ihtml) as extension let developers distinguish in
    a easy way classes, configuration files etc. from web pages.

     
  • Andres Baravalle

    • status: open --> closed
     

Log in to post a comment.