RE: [PHP] securing an 'includes' dir
| From: | Lazor, Ed | Date: | Fri, 28 Jun 2002 17:44:45 +0000 |
| Subject: | RE: [PHP] securing an 'includes' dir | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-104390@lists.php.net to get a copy of this message | ||
The only problem is that making the change in php.ini is global. Doing it
in httpd.conf allows you to localize the change to each virtual host.
-----Original Message-----
From: B i g D o g [mailto:bigdog@venticon.com]
Sent: Friday, June 28, 2002 10:39 AM
To: Lazor, Ed; 'Erik Price'; PHP-General
Subject: Re: [PHP] securing an 'includes' dir
Another way is to set up the include directory in the php.ini file to point
to various directories...
B i g D o g
----- Original Message -----
From: "Lazor, Ed" <ELazor@providence.org>
To: "'Erik Price'" <pricee@hhbrown.com>; "PHP-General"
<php-general@lists.php.net>
Sent: Friday, June 28, 2002 11:27 AM
Subject: RE: [PHP] securing an 'includes' dir
> The includes directory doesn't have to be inside the http root. For
> example, having the following directories:
>
> /www/www.somewhere.com/includes
> /www/www.somewhere.com/htdocs
>
> The htdocs is your http root. You could include a file in index.php like
> this:
>
> include("/www/www.somewhere.com/includes/functions.php");
>
> You could also modify the Apache httpd.conf file and add the path to the
> include directory in the PHP path variable.
>
>
> -----Original Message-----
> > How might I make an 'includes' dir inside the http root and stop users
> > being able to browse it?
>
> chmod go-rwx dirname
>
> But this will probably stop the web server from reading the file.
>
> Perhaps the administrators can provide a script (SUID) that allows a
> user to change the group association of the file to that of the web
> server? Yet without making the user a part of the group itself,
> otherwise all users would be able to see all of these files...
>
>
****************************************************************************
> This message is intended for the sole use of the individual and entity to
> whom it is addressed, and may contain information that is privileged,
> confidential and exempt from disclosure under applicable law. If you are
> not the intended addressee, nor authorized to receive for the intended
> addressee, you are hereby notified that you may not use, copy, disclose or
> distribute to anyone the message or any information contained in the
> message. If you have received this message in error, please immediately
> advise the sender by reply email and delete the message. Thank you very
> much.
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
****************************************************************************
This message is intended for the sole use of the individual and entity to
whom it is addressed, and may contain information that is privileged,
confidential and exempt from disclosure under applicable law. If you are
not the intended addressee, nor authorized to receive for the intended
addressee, you are hereby notified that you may not use, copy, disclose or
distribute to anyone the message or any information contained in the
message. If you have received this message in error, please immediately
advise the sender by reply email and delete the message. Thank you very
much.