Re: securing an 'includes' dir

From: Date: Sun, 30 Jun 2002 19:59:59 +0000
Subject: Re: securing an 'includes' dir
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-104594@lists.php.net to get a copy of this message
Steve Yates wrote:
"Justin French" <justin@indent.com.au> wrote in message news:B9425D5F.9573%justin@indent.com.au...
1. Name all included files .inc
If you name them *.php then put anything in them inside a function, then when the user browses to that file he/she won't see anything at all. I think this is a very poor tactic, because it "covers up" the problem rather than doing anything about it. You still allow people to access your modules directly, and worse, you allow them to execute these modules out of context. By restricting your modules to only allow function declarations, you also make things more difficult on yourself without any real benefit.
It's much better to properly name your included files *.inc as suggested by Mr. French and either: 1. don't put them under document root (my preference) or: 2. configure your Web server to not allow access to .inc files Chris

« previous php.general (#104594) next »