Re: Hiding the source!

From: Date: Thu, 17 Aug 2000 17:47:26 +0000
Subject: Re: Hiding the source!
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-12308@lists.php.net to get a copy of this message
on 8/17/00 10:34 AM, Brian T. Allen (brian@purenetfx.com) wrote: > Another way, with probably the same result (except that the information > wouldn't be parsed) is to add .inc as an extension that won't be displayed > by apache (just like .htaccess is). So even if they type in the URL apache > still won't serve it up. By far the best is to put the includes outside the > web directory. That's a good idea so that people won't be able to see include files at all. However, remember that if anyone else has access to the same server, and PHP is running as a module instead of a setuid cgi, they will be able to find and see all of your includes. All another person needs to do is to make their page say: <?php show_source($document_location); ?> where $document_location is the location of the include file. To find the location, they can do a show source of the page that contains the include file and then look for "include". If the file is in a special include path, they just need to call phpinfo(). So just be careful if you let other users add pages to your site. Paul ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Paul Burney Webmaster and Internet Developer Educational Technology Unit Graduate School of Education and Information Studies University of California, Los Angeles (310) 825-8365 <webmaster@gseis.ucla.edu> <http://www.gseis.ucla.edu/> ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

« previous php.general (#12308) next »