Re: Hiding the source!
| From: | Brian T. Allen | Date: | Thu, 17 Aug 2000 18:02:16 +0000 |
| Subject: | Re: Hiding the source! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12311@lists.php.net to get a copy of this message | ||
True.
I rejoice at the fact I am my own webmaster, own my own hardware, am the
only one with access to my server (root or otherwise), and have my own
bandwidth (T1). I can't imagine doing it any other way (except for perhaps
very reliable co-locating with my own server).
I am not sure I could sleep at night with a less secure server...
Brian
> On Thu, 17 Aug 2000, Paul Burney wrote:
>
> > on 8/17/00 10:34 AM, Brian T. Allen (brian@purenetfx.com) wrote:
> >
> > > Another way, with probably the same result (except that the
information
> > > wouldn't be parsed) is to add .inc as an extension that won't be
displayed
> > > by apache (just like .htaccess is). So even if they type in the URL
apache
> > > still won't serve it up. By far the best is to put the includes
outside the
> > > web directory.
> >
> > That's a good idea so that people won't be able to see include files at
all.
>
> (snip)
>
> > If the file is in a special include path, they just need to call
phpinfo().
> >
> > So just be careful if you let other users add pages to your site.
>
> This could be discouraged to a limited extent by making all include paths
> specific to the user or directory tree, either by defining it in <UserDir>
> in Apache, with .htaccess, or perhaps by VirtualHost (my preference).
>
> Still, it's hardly a reliable solution.
>
> Matt
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net