Re: Authorisation

From: Date: Tue, 04 Jul 2000 08:50:38 +0000
Subject: Re: Authorisation
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-4702@lists.php.net to get a copy of this message
this might not be full proof .. but it works ... for me at least .. what i do is simply put a index.html/index.htm/index.php in the admin directory ... which says a nice cool message about not listing the directory.... this means that down goes your freedom to use the index files.... for other purposes... -------------------------------------------------------------------------------------- SECURITY IS A MYTH........!!!!!!!! "Linux for people with avg. IQ above 98" -------------------------------------------------------------------------------------- Subhrajyoti Moitra ------- C/112 Hall-I email: subhra@iitk.ac.in On Tue, 4 Jul 2000, Mick Lloyd wrote: > I've followed the recent thread on authorisation and have a related > question. I understand how checking user name/password on each page can > control access without the need for .htaccess in the directory where the > pages reside. However, how can one prevent access to the directory through > the browser without using .htaccess. > > For instance, typing www.~.com/~/admin requires authorisation when > .htaccess is present in /admin but when it is not there, it reveals the > directory listing that anyone can view. How can I prevent this happening yet > authorise users via a form and MySQL database check. > > Best regards > > Mick Lloyd > mjl@consultingrooms.com > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#4702) next »