Re: Is this secure enough?

From: Date: Mon, 21 Aug 2000 04:20:15 +0000
Subject: Re: Is this secure enough?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-12711@lists.php.net to get a copy of this message
On 21 Aug, Dave Jones wrote: > But if shell users can read the web pages then they can see the exact > name of the include file. > > To include an include file that is below the web directory would you > use an extra "../" or give it an exact path starting with a "/"? When > you define a path in a php include statement, does a leading "/" define > the root of the machine or the root of the web site? Sure they can see the name - but they may not necessarily have permissions to get at the particular file. When you define the path you are defining a system path, not a 'web root' path. By defining a path, you can then just put the include file name in a script and php will search the path to find it. Now if this path is a) outside the web root structure and b) inaccessible by casual shell users you have some degree of difficultyin them finding and viewing it. Cheers -- David Robley | WEBMASTER & Mail List Admin RESEARCH CENTRE FOR INJURY STUDIES | http://www.nisu.flinders.edu.au/ AusEinet | http://auseinet.flinders.edu.au/ Flinders University, ADELAIDE, SOUTH AUSTRALIA

« previous php.general (#12711) next »