Re: Hiding the source!

From: Date: Thu, 17 Aug 2000 18:02:16 +0000
Subject: Re: Hiding the source!
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-12311@lists.php.net to get a copy of this message
True. I rejoice at the fact I am my own webmaster, own my own hardware, am the only one with access to my server (root or otherwise), and have my own bandwidth (T1). I can't imagine doing it any other way (except for perhaps very reliable co-locating with my own server). I am not sure I could sleep at night with a less secure server... Brian > On Thu, 17 Aug 2000, Paul Burney wrote: > > > on 8/17/00 10:34 AM, Brian T. Allen (brian@purenetfx.com) wrote: > > > > > Another way, with probably the same result (except that the information > > > wouldn't be parsed) is to add .inc as an extension that won't be displayed > > > by apache (just like .htaccess is). So even if they type in the URL apache > > > still won't serve it up. By far the best is to put the includes outside the > > > web directory. > > > > That's a good idea so that people won't be able to see include files at all. > > (snip) > > > If the file is in a special include path, they just need to call phpinfo(). > > > > So just be careful if you let other users add pages to your site. > > This could be discouraged to a limited extent by making all include paths > specific to the user or directory tree, either by defining it in <UserDir> > in Apache, with .htaccess, or perhaps by VirtualHost (my preference). > > Still, it's hardly a reliable solution. > > Matt > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#12311) next »