Re: Security problem?
| From: | Chris Shiflett | Date: | Wed, 26 Jun 2002 01:08:43 +0000 |
| Subject: | Re: Security problem? | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-103868@lists.php.net to get a copy of this message | ||
1LT John W. Holmes wrote:
Or just name it with a php extension. Then the user won't receive anything, either. I always name mine file.inc.php so something similar. Whatever you do, make sure the source isn't sent by apache to the browser. Another option, that I prefer, is to place all modules (.inc files) *outside* of document root, *not* to name them *.php. When combined with the other suggestions given for limiting access to your files with safe mode, etc., it is actually pretty secure.Chris