RE: [PHP-DB] securing directory tree and allowing PHP to work

From: Date: Tue, 20 Aug 2002 21:42:02 +0000
Subject: RE: [PHP-DB] securing directory tree and allowing PHP to work
Groups: php.db 
Request: Send a blank email to php-db+get-21260@lists.php.net to get a copy of this message
Look into the PHP_AUTH_USER variable. It is assigned through basic authentication. Gary Every Sr. UNIX Administrator Ingram Entertainment (615) 287-4876 "Pay It Forward" mailto:gary.every@ingramentertainment.com http://accessingram.com -----Original Message----- From: bmw [mailto:robert.white@online.fr] Sent: Tuesday, August 20, 2002 2:48 AM To: php-db@lists.php.net Subject: [PHP-DB] securing directory tree and allowing PHP to work I am trying to find out how I can secure the directory tree of my PHP scripts from the HTTP server without preventing access to my PHP scripts once in session. Right now, if I type the URL of a subdirectory of my site, I get the index of all the files and directories. Ex: http://domaine/index.html has DB access user login and password for my session authentication to enter into my scripts and run the program. If I type http://domaine/subfolder/ I can see all the PHP code I want without logging into my site. How can I protect the server from doing this without busting access to my scripts through the login from the root level index.html? Apache/1.3.26 (Unix)/Linux mod_fastcgi/2.2.12 mod_perl/1.26 PHP 4.2.2 Robert --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.381 / Virus Database: 214 - Release Date: 02/08/2002 -- PHP Database Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.db (#21260) next »