We have a server with our forum on it. We offer webspace for some of our members if they want to make a site. This is raw webspace, php is allowed, etc., although they only have access to their folder (oursite.com/whatever).
My question is, since this is all on the same server, wouldn't it be possible for someone to write a php script to grab the contents of the vB config file, which would give them the database username/password? Then they could access the database directly?
Am I forgetting about something in vB that secures it from this? If not, is there something I can do to protect it? I have cpanel access, not total control over the server, and I don't want to disable php for everyone anyway. Is there anything else I should know?
My question is, since this is all on the same server, wouldn't it be possible for someone to write a php script to grab the contents of the vB config file, which would give them the database username/password? Then they could access the database directly?
Am I forgetting about something in vB that secures it from this? If not, is there something I can do to protect it? I have cpanel access, not total control over the server, and I don't want to disable php for everyone anyway. Is there anything else I should know?
Comment