Re: securing an 'includes' dir
| From: | Richard Lynch | Date: | Tue, 02 Jul 2002 07:41:54 +0000 |
| Subject: | Re: securing an 'includes' dir | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-104866@lists.php.net to get a copy of this message | ||
>"Justin French" <justin@indent.com.au> wrote in message
>news:B9425D5F.9573%justin@indent.com.au...
>> 1. Name all included files .inc
>
> If you name them *.php then put anything in them inside a function, then
>when the user browses to that file he/she won't see anything at all.
You've already moved them out of the web tree so that they can't browse to
them in the first place...
It's better to clearly denote them as *NOT* "entry point" .php (or .htm)
files than to possibly upload them into htdocs.
When you see .inc in htdocs, you know you screwed up. Vice versa for .php
in your includes directory, which is not in htdocs.
Works for me. :-)
YMMV.
--
Like Music? http://l-i-e.com/artists.htm