Re: securing an 'includes' dir

From: Date: Tue, 02 Jul 2002 07:41:54 +0000
Subject: Re: securing an 'includes' dir
Groups: php.general 
Request: Send a blank email to php-general+get-104866@lists.php.net to get a copy of this message
>"Justin French" <justin@indent.com.au> wrote in message >news:B9425D5F.9573%justin@indent.com.au... >> 1. Name all included files .inc > > If you name them *.php then put anything in them inside a function, then >when the user browses to that file he/she won't see anything at all. You've already moved them out of the web tree so that they can't browse to them in the first place... It's better to clearly denote them as *NOT* "entry point" .php (or .htm) files than to possibly upload them into htdocs. When you see .inc in htdocs, you know you screwed up. Vice versa for .php in your includes directory, which is not in htdocs. Works for me. :-) YMMV. -- Like Music? http://l-i-e.com/artists.htm

« previous php.general (#104866) next »