Re: securing an 'includes' dir

From: Date: Fri, 28 Jun 2002 17:39:25 +0000
Subject: Re: securing an 'includes' dir
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-104387@lists.php.net to get a copy of this message
Another way is to set up the include directory in the php.ini file to point to various directories... B i g D o g ----- Original Message ----- From: "Lazor, Ed" <ELazor@providence.org> To: "'Erik Price'" <pricee@hhbrown.com>; "PHP-General" <php-general@lists.php.net> Sent: Friday, June 28, 2002 11:27 AM Subject: RE: [PHP] securing an 'includes' dir > The includes directory doesn't have to be inside the http root. For > example, having the following directories: > > /www/www.somewhere.com/includes > /www/www.somewhere.com/htdocs > > The htdocs is your http root. You could include a file in index.php like > this: > > include("/www/www.somewhere.com/includes/functions.php"); > > You could also modify the Apache httpd.conf file and add the path to the > include directory in the PHP path variable. > > > -----Original Message----- > > How might I make an 'includes' dir inside the http root and stop users > > being able to browse it? > > chmod go-rwx dirname > > But this will probably stop the web server from reading the file. > > Perhaps the administrators can provide a script (SUID) that allows a > user to change the group association of the file to that of the web > server? Yet without making the user a part of the group itself, > otherwise all users would be able to see all of these files... > > **************************************************************************** > This message is intended for the sole use of the individual and entity to > whom it is addressed, and may contain information that is privileged, > confidential and exempt from disclosure under applicable law. If you are > not the intended addressee, nor authorized to receive for the intended > addressee, you are hereby notified that you may not use, copy, disclose or > distribute to anyone the message or any information contained in the > message. If you have received this message in error, please immediately > advise the sender by reply email and delete the message. Thank you very > much. > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.general (#104387) next »