Re: php code visibility
| From: | Steve Edberg | Date: | Fri, 04 Aug 2000 01:20:26 +0000 |
| Subject: | Re: php code visibility | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-10057@lists.php.net to get a copy of this message | ||
At 04:01 PM 8/3/00 , Michael Richardson wrote:
Thanks in advance for your time: I need some documentation and concrete knowledge that supports or disproves the theory that php code can be viewed directly if it is in the web (www / htdocs) directory instead of a secure sub-folder. Can a person, in fact, get the php document returned directly so that they can view the source code before it is parsed by the php parser? Please, if you have knowledge of where I may find the truth in this discussion, respond.In general - as Zeev said in another post - you're safe with a properly configured web server. There's an exception for some Windows based systems, though. (Disclaimer: momory somewhat fuzzy on this one) I think this only affected MS-IIS 3, but it worked for ANY scripts - Perl, ASP, PHP, whatever. If the string '::$DATA' (without the quotes) was appended to the URL, IIS would bypass script execution and send back the script as text. This had to do with a MS filesystem kludge for accommodating compound objects, as I recall. And just to add a little to what Zeev said about include files using the '.inc' extension. Indeed, if the server doesn't know what that extension is, it might send it back as raw text, exposing code and possibly passwords. That's a very good reason to put included files outside the web server's htdocs file tree; just set up the appropriate include path in httpd.conf, .htaccess or php.ini. +- Obscure computer humor, item 77: -------------------------------------+
| Steve Edberg University of California, Davis | | sbedberg@ucdavis.edu (530)754-9127 | | http://aesric.ucdavis.edu/ http://pgfsun.ucdavis.edu/ |+------------------- How are cats and UNIVAC EXEC-8 similar? Fur. Purr. -+