Re: php code visibility
| From: | Zeev Suraski | Date: | Thu, 03 Aug 2000 23:27:03 +0000 |
| Subject: | Re: php code visibility | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-10047@lists.php.net to get a copy of this message | ||
Assuming the server is properly-configured, it's quite impossible to get
to the source code of your PHP scripts. However, misconfiguring the
server gives you enough rope to hang yourself in a variety of ways, and if
you seriously misconfigure your server, it may be possible to get to the
source code of your scripts. Note that this is *extremely* unlikely, and
assuming you've followed the installation instructions, and haven't messed
up with your server's configuration too much, you should be safe.
One important thing to notice is that when using include files, if you use
a different extension for them (e.g. ".inc"), it'll be possible to obtain
them, unless you explicitly prevent it in the server configuration.
Zeev
On Thu, 3 Aug 2000, Michael Richardson wrote:
> Thanks in advance for your time:
>
> I need some documentation and concrete knowledge that supports or disproves
> the theory that php code can be viewed directly if it is in the web (www /
> htdocs) directory instead of a secure sub-folder. Can a person, in fact,
> get the php document returned directly so that they can view the source code
> before it is parsed by the php parser?
>
> Please, if you have knowledge of where I may find the truth in this
> discussion, respond.
>
> RW
>
>
--
Zeev Suraski <zeev@zend.com>
http://www.zend.com/