Re: Hiding .inc
| From: | Christopher W. Curtis | Date: | Fri, 08 Sep 2000 23:49:57 +0000 |
| Subject: | Re: Hiding .inc | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15967@lists.php.net to get a copy of this message | ||
Lars Torben Wilson wrote:
>
> Christopher W. Curtis writes:
> > William S Poarch wrote:
> > >
> > > We're setting up a site on a virtual server that includes data we want to be
> > > secure in .inc files.
> > > What is the best way to keep these files from being able to be accessed by
> > > people who might be looking for security holes?
> >
> > Rename them .php
> >
> > Chris
>
> This method seems a bit subject to error--it is conceivable that the
> site maintainers could commit an oops and not have .php files parsed
> by PHP, if only briefly (say, right after an upgrade).
Well, you're screwed then because the PHP file doing the include will be
visible during this time as well, unless you mean to make the security
for the first file rock-solid and just put anything in the include file,
kinda like:
index.php:
<?php Require( "realscript.inc" ); ?>
But maybe I'm just not paranoid enough.
Chris