Also, I recommend changing "config.php" to something as obscure as possible, as it's easy to read the contents of a folder in a php file.
Calling it "configuration.php" or "mynewconfig.php", even in another directory, doesn't make it particularly difficult for a hacker to figure out where your config.php has gone, if he wants to hack your site and already has the means to put a malicious file onto your server.