vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Access to the config.php file??? (https://vborg.vbsupport.ru/showthread.php?t=105627)

SnappedAgain 01-18-2006 07:41 AM

Access to the config.php file???
 
I was just wondering, couldn't someone who knows how vb works just download the config.php file and get access to the mysql username and password? There's gotta be some way to protect this from happening. I was thinking I could just make the includes directory access restricted but then I would think that vb wouldn't be able to access the file :ermm: Am I missing something here :speechless:

HMBeaty 01-18-2006 10:07 PM

Just put an .htaccess file in there basically password protecting that directory and you should be fine

Paul M 01-18-2006 10:41 PM

No, you cannot just download it. Because it's a php file apache processes it and supplies you the output, not the source.

rasp187 01-19-2006 03:13 AM

There have been a few reported cases of an Apache error in which case the php file gets downloaded (this happened to me once, too) so ever since then I've had htaccess set up on my /includes/ folder.

Really the AdminCP and ModCP are the only two folders that *should* have htaccess enabled on them. I currently use htaccess for the install, includes, and admincp folders.

baronvonwalz 01-19-2006 03:17 AM

The only time a php file would get downloaded is in the event that the PHP libraries aren't working.

SnappedAgain 01-19-2006 03:26 AM

Quote:

Originally Posted by Paul M
No, you cannot just download it. Because it's a php file apache processes it and supplies you the output, not the source.

ahh i see, so does this work the same in abyss x2 as well?

I just tried to download the file and I save it to the desktop and it says downloading and then says its completed but then the file never appears.. Im assuming this is the security measure that is taken..

Guest210212002 01-19-2006 03:27 AM

Ideally, what should the contents of that .htaccess be?

HMBeaty 01-19-2006 03:29 AM

Quote:

Originally Posted by Chris-777
Ideally, what should the contents of that .htaccess be?

Hang on a sec....I'll find it for you

But generally a username and an encrypted password for that particular directory your protecting

http://www.www-ss.com/tutorials/htaccess/htaccess.htm

Guest210212002 01-19-2006 03:40 AM

Solid, thank you very much.

/me bookmarks that for coming over at work tomorrow.

HMBeaty 01-19-2006 03:41 AM

You're welcome (assuming that was directed towards me)


All times are GMT. The time now is 05:11 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01061 seconds
  • Memory Usage 1,728KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete