Re: securing an 'includes' dir

From: Date: Fri, 28 Jun 2002 17:49:48 +0000
Subject: Re: securing an 'includes' dir
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-104391@lists.php.net to get a copy of this message
Good call for the hosted guys and the virtual... You can added this also in the .htpasswd file added to the htdoc-root directory. This will allow you to do it if you are not able to access the httpd.conf file for the hosted guys as well... B i g D o G ----- Original Message ----- From: "Lazor, Ed" <ELazor@providence.org> To: "'B i g D o g'" <bigdog@venticon.com>; "Lazor, Ed" <ELazor@providence.org>; "'Erik Price'" <pricee@hhbrown.com>; "PHP-General" <php-general@lists.php.net> Sent: Friday, June 28, 2002 11:44 AM Subject: RE: [PHP] securing an 'includes' dir > The only problem is that making the change in php.ini is global. Doing it > in httpd.conf allows you to localize the change to each virtual host. > > -----Original Message----- > From: B i g D o g [mailto:bigdog@venticon.com] > Sent: Friday, June 28, 2002 10:39 AM > To: Lazor, Ed; 'Erik Price'; PHP-General > Subject: Re: [PHP] securing an 'includes' dir > > > Another way is to set up the include directory in the php.ini file to point > to various directories... > > > B i g D o g > > > ----- Original Message ----- > From: "Lazor, Ed" <ELazor@providence.org> > To: "'Erik Price'" <pricee@hhbrown.com>; "PHP-General" > <php-general@lists.php.net> > Sent: Friday, June 28, 2002 11:27 AM > Subject: RE: [PHP] securing an 'includes' dir > > > > The includes directory doesn't have to be inside the http root. For > > example, having the following directories: > > > > /www/www.somewhere.com/includes > > /www/www.somewhere.com/htdocs > > > > The htdocs is your http root. You could include a file in index.php like > > this: > > > > include("/www/www.somewhere.com/includes/functions.php"); > > > > You could also modify the Apache httpd.conf file and add the path to the > > include directory in the PHP path variable. > > > > > > -----Original Message----- > > > How might I make an 'includes' dir inside the http root and stop users > > > being able to browse it? > > > > chmod go-rwx dirname > > > > But this will probably stop the web server from reading the file. > > > > Perhaps the administrators can provide a script (SUID) that allows a > > user to change the group association of the file to that of the web > > server? Yet without making the user a part of the group itself, > > otherwise all users would be able to see all of these files... > > > > > **************************************************************************** > > This message is intended for the sole use of the individual and entity to > > whom it is addressed, and may contain information that is privileged, > > confidential and exempt from disclosure under applicable law. If you are > > not the intended addressee, nor authorized to receive for the intended > > addressee, you are hereby notified that you may not use, copy, disclose or > > distribute to anyone the message or any information contained in the > > message. If you have received this message in error, please immediately > > advise the sender by reply email and delete the message. Thank you very > > much. > > > > -- > > PHP General Mailing List (http://www.php.net/) > > To unsubscribe, visit: http://www.php.net/unsub.php > > **************************************************************************** > This message is intended for the sole use of the individual and entity to > whom it is addressed, and may contain information that is privileged, > confidential and exempt from disclosure under applicable law. If you are > not the intended addressee, nor authorized to receive for the intended > addressee, you are hereby notified that you may not use, copy, disclose or > distribute to anyone the message or any information contained in the > message. If you have received this message in error, please immediately > advise the sender by reply email and delete the message. Thank you very > much.

« previous php.general (#104391) next »