DEV Community

Discussion on: What are the worst security practices you've ever witnessed?

matthias profile image
Matthias 🤖

In the early days of web development many people stored database secrets in *.inc files which were then included with PHP.
Unfortunately those *.inc files were publicly accessible because the Apache web server served them as plain text.