Re: security help

From: Date: Thu, 08 Feb 2001 21:26:23 +0000
Subject: Re: security help
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-38822@lists.php.net to get a copy of this message
"James, Yz" wrote: > > In addition, > > (if using .htaccess) They would only be able to read the .htpasswd from > public directory if they had first authorised themselves. The browser will > prompt them to identify before it allows files from a protected directory to > be included. > James, are you sure about this? Afaik, no user authentication applies to PHP include() calls. This would require PHP to integrate much closer with Apache than I think it does (and makes sense). Cheers, Ben > J. > > > Make sure that the .htpasswd file is BELOW the public files root. That > way, > > it can't be accessed through a browser, unless the person who has written > > the file to try and read the .htpasswd has uploaded their file to the > server > > it resides on, and has permission to access that low level directory. > They > > can't read files in a directory route, unless they're in the directory: > So > > a URL reference won't work. If you've uploaded the .htpasswd to > /www/admin > > They could do an include for: > > > > <? > > include(http://www.yoursite.com/admin/.htpasswd); > > ?> > > > > ..................So: > > > > /home/myfiles/.htpasswd > > > > Rather than > > > > /home/myfiles/publicwwwfiles/.htpasswd > > > > Hope that's of some use to you. > > James. > > > > ""Thor M. Steindorsson"" <thor@netwood.net> wrote in message > > news:CGEILHNPHENDKFJOEGFKKEKGCOAA.thor@netwood.net... > > > Should this be possible? > > > I know this isn't an issue with php, but since I used php to do this, I > > > figured maybe someone here has encountered the same thing, and knows how > > to > > > help. > > > Is this something that can be fixed by making some changes on the linux > > > server? > > > > > > By using this: > > > > > > <? > > > echo "<pre>"; > > > include("/home/someuser/www/admin/.htaccess"); > > > echo "</pre>"; > > > ?> > > > > > > I can see what .htpasswd file is used, and then I can simply change the > > code > > > to display that particular password file, then take the encrypted > > password, > > > and decrypt it to gain access to that protected area. > > > > > > I have a feeling this is a permissions issue on the Linux server... > > > Can anyone point me in the right direction with this? > > > > > > > > > -- > > > PHP General Mailing List (http://www.php.net/) > > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > > > For additional commands, e-mail: php-general-help@lists.php.net > > > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > > > > > > > > > -- > > PHP General Mailing List (http://www.php.net/) > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > > For additional commands, e-mail: php-general-help@lists.php.net > > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#38822) next »