Re: Is this secure enough?
| From: | David Robley | Date: | Mon, 21 Aug 2000 04:20:15 +0000 |
| Subject: | Re: Is this secure enough? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12711@lists.php.net to get a copy of this message | ||
On 21 Aug, Dave Jones wrote:
> But if shell users can read the web pages then they can see the exact
> name of the include file.
>
> To include an include file that is below the web directory would you
> use an extra "../" or give it an exact path starting with a "/"? When
> you define a path in a php include statement, does a leading "/" define
> the root of the machine or the root of the web site?
Sure they can see the name - but they may not necessarily have
permissions to get at the particular file.
When you define the path you are defining a system path, not a 'web
root' path. By defining a path, you can then just put the include file
name in a script and php will search the path to find it. Now if this
path is a) outside the web root structure and b) inaccessible by casual
shell users you have some degree of difficultyin them finding and
viewing it.
Cheers
--
David Robley | WEBMASTER & Mail List Admin
RESEARCH CENTRE FOR INJURY STUDIES | http://www.nisu.flinders.edu.au/
AusEinet | http://auseinet.flinders.edu.au/
Flinders University, ADELAIDE, SOUTH AUSTRALIA