RE: [PHP] .inc files
| From: | Maxim Maletsky | Date: | Tue, 03 Oct 2000 09:59:02 +0000 |
| Subject: | RE: [PHP] .inc files | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-18395@lists.php.net to get a copy of this message | ||
The reply above was very clear, though.
Just to explain one detail in case you didn't know, every text file with PHP
code in it, if include()d will work.
What you need to do is to move them out the root, in other words where
browser cannot reach, before your /index.html.
But the easiest way to fix it is simply to set .inc to be parsed in Apache.
Renaming can be a b...ch, but you could include then in each .inc file a
relative .php file, so even if someone gets to the page he will see that an
inclusion has failed, however to see the relative .php page will be
impossible.
Even easier is to password-protect the directory where all your .inc files
reside, always of course if you used to have .inc files organized somewhere.
-----Original Message-----
From: Abe Asghar [mailto:abe@fish.tm]
Sent: Tuesday, October 03, 2000 6:31 PM
To: php-general@lists.php.net
Subject: [PHP] .inc files
Hi Guys,
I am using a separate .inc file for the navigation on my website. However
if someone goes to the browser and types 'whatever'.inc - they get a listing
of all the PHP include file-
The page works fine but this gaping security hole gave me a bit of a shock -
Anyone know how to get around it?
Thanks,
Abe
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net