Re: [PHP] Your opinion on security issue: file extension

2001-05-01 Thread Yasuo Ohgaki
I think expose_php = Off is first thing to do instead of changing association. (As well as disabling server signature) extension does not tell much, but expose_php tells PHP version also, if you care about crackers. Crackers will notice you care about security somewhat. It does not protect your

Re: [PHP] Your opinion on security issue: file extension

2001-05-01 Thread Jon Rosenberg
Not really, I mean it may deter a very novice hacker. But, if the people want in, they can very easily find out what server and server software you are running. For example, goto www.netcraft.com and click on 'What's that site running?' and put in your www.domain.com address. It will tell ou ev