Re: securing an 'includes' dir
| From: | B i g D o g | Date: | Fri, 28 Jun 2002 17:39:25 +0000 |
| Subject: | Re: securing an 'includes' dir | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104387@lists.php.net to get a copy of this message | ||
Another way is to set up the include directory in the php.ini file to point
to various directories...
B i g D o g
----- Original Message -----
From: "Lazor, Ed" <ELazor@providence.org>
To: "'Erik Price'" <pricee@hhbrown.com>; "PHP-General"
<php-general@lists.php.net>
Sent: Friday, June 28, 2002 11:27 AM
Subject: RE: [PHP] securing an 'includes' dir
> The includes directory doesn't have to be inside the http root. For
> example, having the following directories:
>
> /www/www.somewhere.com/includes
> /www/www.somewhere.com/htdocs
>
> The htdocs is your http root. You could include a file in index.php like
> this:
>
> include("/www/www.somewhere.com/includes/functions.php");
>
> You could also modify the Apache httpd.conf file and add the path to the
> include directory in the PHP path variable.
>
>
> -----Original Message-----
> > How might I make an 'includes' dir inside the http root and stop users
> > being able to browse it?
>
> chmod go-rwx dirname
>
> But this will probably stop the web server from reading the file.
>
> Perhaps the administrators can provide a script (SUID) that allows a
> user to change the group association of the file to that of the web
> server? Yet without making the user a part of the group itself,
> otherwise all users would be able to see all of these files...
>
>
****************************************************************************
> This message is intended for the sole use of the individual and entity to
> whom it is addressed, and may contain information that is privileged,
> confidential and exempt from disclosure under applicable law. If you are
> not the intended addressee, nor authorized to receive for the intended
> addressee, you are hereby notified that you may not use, copy, disclose or
> distribute to anyone the message or any information contained in the
> message. If you have received this message in error, please immediately
> advise the sender by reply email and delete the message. Thank you very
> much.
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php