RE: [PHP] Security problem?

From: Date: Wed, 26 Jun 2002 13:29:35 +0000
Subject: RE: [PHP] Security problem?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-103963@lists.php.net to get a copy of this message
> On Tuesday, June 25, 2002, at 08:26 PM, Analysis & Solutions wrote: > > > I usually run PHP as CGI. My secure files are kept in a directory > > that's > > not under the */docroot. Thus, they can't be gotten to through the web > > server at all. Plus, the secure files are chmoded 600 (which means they > > can be read/written only by the owner). Thereby, the only user on the > > server who can read them is me. > > Tradeoff, huh? If I understand it correctly, you can't keep the files > outside the docroot if you're using mod_php b/c the web server itself is > what fetches the file (therefore it needs to be in the docroot). But > mod_php is faster than CGI PHP and can handle more simultaneous > requests. Right? Yes you can. Apache can read any file it has access to. Include('/home/user/includes/myfile.php'); Works just as well as Include('/home/user/www/includes/myfile.php'); Where /home/user/www is your web root. ---John Holmes...

« previous php.general (#103963) next »