Re: Hiding the source!
| From: | Paul Burney | Date: | Thu, 17 Aug 2000 17:47:26 +0000 |
| Subject: | Re: Hiding the source! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12308@lists.php.net to get a copy of this message | ||
on 8/17/00 10:34 AM, Brian T. Allen (brian@purenetfx.com) wrote:
> Another way, with probably the same result (except that the information
> wouldn't be parsed) is to add .inc as an extension that won't be displayed
> by apache (just like .htaccess is). So even if they type in the URL apache
> still won't serve it up. By far the best is to put the includes outside the
> web directory.
That's a good idea so that people won't be able to see include files at all.
However, remember that if anyone else has access to the same server, and PHP
is running as a module instead of a setuid cgi, they will be able to find
and see all of your includes.
All another person needs to do is to make their page say:
<?php
show_source($document_location);
?>
where $document_location is the location of the include file.
To find the location, they can do a show source of the page that contains
the include file and then look for "include".
If the file is in a special include path, they just need to call phpinfo().
So just be careful if you let other users add pages to your site.
Paul
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Paul Burney
Webmaster and Internet Developer
Educational Technology Unit
Graduate School of Education and Information Studies
University of California, Los Angeles
(310) 825-8365
<webmaster@gseis.ucla.edu>
<http://www.gseis.ucla.edu/>
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++