Re: Protecting Include remote files

From: Date: Thu, 29 Jun 2000 05:34:14 +0000
Subject: Re: Protecting Include remote files
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-3735@lists.php.net to get a copy of this message
You can configure your httpd.conf file to allow this. Browse your httpd.conf file looking for <Directory></Directory> and <Files></Files> sections to see this in action. It uses .ht file access rights. I have my server currently blocking direct file transfers for .php4, .class, and .inc files from anywhere. -Szii At 11:48 PM 6/28/00 -0500, Reuben D Budiardja wrote: > >Hi, > >I have two server running php. One of them connect with Oracle, and >have been used for Php application for administration in my institution, >and only a certain user can use it (let's call it server1). The second >server is only a web server (server2). > >Now, I am creating an application in server1 (using database and stuff). I >want to displayed to public, thus I include the application page in >server2. So, in server2, I would have something like >include ('http://server1.domain.com/blah.php3'); . > >My question is, can I protect that application in server1 (blah.php3) so >that it cannot be included by anyone except by server2 ? I mean, if I know >the URL address for the application in server1, I can use any server, >serverX, to include that application in my page right? Is there anyway to >avoid this? > >Thanks. >Reuben D. Budiardja > > > > > >-- >PHP General Mailing List (http://www.php.net/) >To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net >For additional commands, e-mail: php-general-help@lists.php.net >To contact the list administrators, e-mail: php-list-admin@lists.php.net > > >

« previous php.general (#3735) next »