Re: Protecting Include remote files
| From: | Szii | Date: | Thu, 29 Jun 2000 05:34:14 +0000 |
| Subject: | Re: Protecting Include remote files | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-3735@lists.php.net to get a copy of this message | ||
You can configure your httpd.conf file to allow this. Browse your
httpd.conf file looking for <Directory></Directory> and <Files></Files>
sections to see this in action. It uses .ht file access rights.
I have my server currently blocking direct file transfers for
.php4, .class, and .inc files from anywhere.
-Szii
At 11:48 PM 6/28/00 -0500, Reuben D Budiardja wrote:
>
>Hi,
>
>I have two server running php. One of them connect with Oracle, and
>have been used for Php application for administration in my institution,
>and only a certain user can use it (let's call it server1). The second
>server is only a web server (server2).
>
>Now, I am creating an application in server1 (using database and stuff). I
>want to displayed to public, thus I include the application page in
>server2. So, in server2, I would have something like
>include ('http://server1.domain.com/blah.php3'); .
>
>My question is, can I protect that application in server1 (blah.php3) so
>that it cannot be included by anyone except by server2 ? I mean, if I know
>the URL address for the application in server1, I can use any server,
>serverX, to include that application in my page right? Is there anyway to
>avoid this?
>
>Thanks.
>Reuben D. Budiardja
>
>
>
>
>
>--
>PHP General Mailing List (http://www.php.net/)
>To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
>For additional commands, e-mail: php-general-help@lists.php.net
>To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
>