Re: securing an 'includes' dir
| From: | Richard Lynch | Date: | Tue, 02 Jul 2002 20:12:12 +0000 |
| Subject: | Re: securing an 'includes' dir | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-105034@lists.php.net to get a copy of this message | ||
>>> "Justin French" <justin@indent.com.au> wrote in message
>>> news:B9425D5F.9573%justin@indent.com.au...
>>>> 1. Name all included files .inc
>>>
>>> If you name them *.php then put anything in them inside a function, then
>>> when the user browses to that file he/she won't see anything at all.
>>
>> You've already moved them out of the web tree so that they can't browse to
>> them in the first place...
>
>Actually, the OP was about securing an includes directory which COULD NOT be
>placed outside the docroot.
Change web hosts. :-)
Seriously.
It's cheaper than buying the Zend Encoder (or knock-off copies thereof),
which is your only other real alternative.
The rest of your options aren't worth considering, unless you just don't
care if your db data is publicly write-able or not.
--
Like Music? http://l-i-e.com/artists.htm