Re: Keeping "Secrets" in PHP Files
| From: | Jason Wong | Date: | Fri, 28 Jun 2002 14:11:05 +0000 |
| Subject: | Re: Keeping "Secrets" in PHP Files | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104333@lists.php.net to get a copy of this message | ||
On Friday 28 June 2002 21:51, Jonathan Rosenberg wrote:
> Thanks for the reply. But changing the ground read permission of
> the PHP files wouldn't help, either, would it? Because the other
> users who have web sites can just create a PHP file that reads my
> PHP files from one of their pages (which would be running in
> group "websecret").
>
> Seems like this just opens up the same hole. Yes?
You can try the following:
1) Make a directory under your web docroot where all your 'secret' files can
be kept.
2) Make sure your 'secret' files are named extremely obscurely as to be
'unguessable'.
3) Then "chmod ugo-r" your 'secret' directory.
This prevents the directory contents from being listed, thus unless people
know the names of your secret files they won't be able to access them.
--
Jason Wong -> Gremlins Associates -> www.gremlins.com.hk
Open Source Software Systems Integrators
* Web Design & Hosting * Internet & Intranet Applications Development *
/*
This sentence does in fact not have the property it claims not to have.
*/