Re: Authorisation
| From: | Subhrajyoti Moitra | Date: | Tue, 04 Jul 2000 08:50:38 +0000 |
| Subject: | Re: Authorisation | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-4702@lists.php.net to get a copy of this message | ||
this might not be full proof .. but it works ... for me at least ..
what i do is simply put a index.html/index.htm/index.php in the
admin directory ... which says a nice cool message about not listing the
directory....
this means that down goes your freedom to use the index files.... for
other purposes...
--------------------------------------------------------------------------------------
SECURITY IS A MYTH........!!!!!!!!
"Linux for people with avg. IQ above 98"
--------------------------------------------------------------------------------------
Subhrajyoti Moitra ------- C/112 Hall-I
email: subhra@iitk.ac.in
On Tue, 4 Jul 2000, Mick Lloyd wrote:
> I've followed the recent thread on authorisation and have a related
> question. I understand how checking user name/password on each page can
> control access without the need for .htaccess in the directory where the
> pages reside. However, how can one prevent access to the directory through
> the browser without using .htaccess.
>
> For instance, typing www.~.com/~/admin requires authorisation when
> .htaccess is present in /admin but when it is not there, it reveals the
> directory listing that anyone can view. How can I prevent this happening yet
> authorise users via a form and MySQL database check.
>
> Best regards
>
> Mick Lloyd
> mjl@consultingrooms.com
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>