Re: securing an 'includes' dir
| From: | Chris Shiflett | Date: | Sun, 30 Jun 2002 19:59:59 +0000 |
| Subject: | Re: securing an 'includes' dir | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104594@lists.php.net to get a copy of this message | ||
Steve Yates wrote:
"Justin French" <justin@indent.com.au> wrote in message news:B9425D5F.9573%justin@indent.com.au...It's much better to properly name your included files *.inc as suggested by Mr. French and either: 1. don't put them under document root (my preference) or: 2. configure your Web server to not allow access to .inc files Chris1. Name all included files .incIf you name them *.php then put anything in them inside a function, then when the user browses to that file he/she won't see anything at all. I think this is a very poor tactic, because it "covers up" the problem rather than doing anything about it. You still allow people to access your modules directly, and worse, you allow them to execute these modules out of context. By restricting your modules to only allow function declarations, you also make things more difficult on yourself without any real benefit.