Re: Hiding .inc

From: Date: Fri, 08 Sep 2000 23:49:57 +0000
Subject: Re: Hiding .inc
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-15967@lists.php.net to get a copy of this message
Lars Torben Wilson wrote: > > Christopher W. Curtis writes: > > William S Poarch wrote: > > > > > > We're setting up a site on a virtual server that includes data we want to be > > > secure in .inc files. > > > What is the best way to keep these files from being able to be accessed by > > > people who might be looking for security holes? > > > > Rename them .php > > > > Chris > > This method seems a bit subject to error--it is conceivable that the > site maintainers could commit an oops and not have .php files parsed > by PHP, if only briefly (say, right after an upgrade). Well, you're screwed then because the PHP file doing the include will be visible during this time as well, unless you mean to make the security for the first file rock-solid and just put anything in the include file, kinda like: index.php: <?php Require( "realscript.inc" ); ?> But maybe I'm just not paranoid enough. Chris

« previous php.general (#15967) next »