Re: securing an 'includes' dir
| From: | B i g D o g | Date: | Fri, 28 Jun 2002 17:49:48 +0000 |
| Subject: | Re: securing an 'includes' dir | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104391@lists.php.net to get a copy of this message | ||
Good call for the hosted guys and the virtual...
You can added this also in the .htpasswd file added to the htdoc-root
directory. This will allow you to do it if you are not able to access the
httpd.conf file for the hosted guys as well...
B i g D o G
----- Original Message -----
From: "Lazor, Ed" <ELazor@providence.org>
To: "'B i g D o g'" <bigdog@venticon.com>; "Lazor, Ed"
<ELazor@providence.org>; "'Erik Price'" <pricee@hhbrown.com>;
"PHP-General"
<php-general@lists.php.net>
Sent: Friday, June 28, 2002 11:44 AM
Subject: RE: [PHP] securing an 'includes' dir
> The only problem is that making the change in php.ini is global. Doing it
> in httpd.conf allows you to localize the change to each virtual host.
>
> -----Original Message-----
> From: B i g D o g [mailto:bigdog@venticon.com]
> Sent: Friday, June 28, 2002 10:39 AM
> To: Lazor, Ed; 'Erik Price'; PHP-General
> Subject: Re: [PHP] securing an 'includes' dir
>
>
> Another way is to set up the include directory in the php.ini file to
point
> to various directories...
>
>
> B i g D o g
>
>
> ----- Original Message -----
> From: "Lazor, Ed" <ELazor@providence.org>
> To: "'Erik Price'" <pricee@hhbrown.com>; "PHP-General"
> <php-general@lists.php.net>
> Sent: Friday, June 28, 2002 11:27 AM
> Subject: RE: [PHP] securing an 'includes' dir
>
>
> > The includes directory doesn't have to be inside the http root. For
> > example, having the following directories:
> >
> > /www/www.somewhere.com/includes
> > /www/www.somewhere.com/htdocs
> >
> > The htdocs is your http root. You could include a file in index.php
like
> > this:
> >
> > include("/www/www.somewhere.com/includes/functions.php");
> >
> > You could also modify the Apache httpd.conf file and add the path to the
> > include directory in the PHP path variable.
> >
> >
> > -----Original Message-----
> > > How might I make an 'includes' dir inside the http root and stop users
> > > being able to browse it?
> >
> > chmod go-rwx dirname
> >
> > But this will probably stop the web server from reading the file.
> >
> > Perhaps the administrators can provide a script (SUID) that allows a
> > user to change the group association of the file to that of the web
> > server? Yet without making the user a part of the group itself,
> > otherwise all users would be able to see all of these files...
> >
> >
>
****************************************************************************
> > This message is intended for the sole use of the individual and entity
to
> > whom it is addressed, and may contain information that is privileged,
> > confidential and exempt from disclosure under applicable law. If you
are
> > not the intended addressee, nor authorized to receive for the intended
> > addressee, you are hereby notified that you may not use, copy, disclose
or
> > distribute to anyone the message or any information contained in the
> > message. If you have received this message in error, please immediately
> > advise the sender by reply email and delete the message. Thank you very
> > much.
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, visit: http://www.php.net/unsub.php
>
>
****************************************************************************
> This message is intended for the sole use of the individual and entity to
> whom it is addressed, and may contain information that is privileged,
> confidential and exempt from disclosure under applicable law. If you are
> not the intended addressee, nor authorized to receive for the intended
> addressee, you are hereby notified that you may not use, copy, disclose or
> distribute to anyone the message or any information contained in the
> message. If you have received this message in error, please immediately
> advise the sender by reply email and delete the message. Thank you very
> much.