Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Off course, but in this case, passwords would only be exposed if the config file had a miss-typed opening PHP tag. If "test.php" had it, you wouldn't be able to see the contents of "test2.php".


Yes, you are right. And in this exact case they (mis-)edited the file, that contained passwords (i.e. test2.php in my improvised example).


Sure, I was replying for this hypothetical situation that you guys ware discussing, where they would store passwords in a different file outside of webroot ...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: