RE: [PHP] Security of PHP code
| From: | Hankley, Chip | Date: | Wed, 04 Jul 2001 15:45:41 +0000 |
| Subject: | RE: [PHP] Security of PHP code | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-56186@lists.php.net to get a copy of this message | ||
OK,
I'm pretty new to PHP, and have been reading this thread, and am just a
little freaked.
If I understand this right, the only way reason we can view the source code
of those pages is that the web server on which the page resides essentially
has a PHP page somewhere on their site that has some variation of:
<?show_source($file);?>
as it's content, right?
While I can see the utility of that for some situations
(teaching...examples, etc.), it seems like a huge potential for security
breaches.
Is it possible to have such a function on your site w/o giving access to ALL
of your documents...
Chip