RE: [PHP] Security of PHP code

From: Date: Wed, 04 Jul 2001 15:54:59 +0000
Subject: RE: [PHP] Security of PHP code
Groups: php.general 
Request: Send a blank email to php-general+get-56188@lists.php.net to get a copy of this message
Yes, I would have thought this would do it: if (strstr($file, "/usr/local/apache/htdocs/") { show_source($file); } else { echo "File must be in /usr/local/apache/htdocs!"; } Modify as appropriate. Have I missed anything, or will this do the trick? Cheers Jon -----Original Message----- From: Hankley, Chip [mailto:Chip.Hankley@GASAI.Com] Sent: 04 July 2001 16:46 To: PHP Mailingliste Subject: RE: [PHP] Security of PHP code OK, I'm pretty new to PHP, and have been reading this thread, and am just a little freaked. If I understand this right, the only way reason we can view the source code of those pages is that the web server on which the page resides essentially has a PHP page somewhere on their site that has some variation of: <?show_source($file);?> as it's content, right? While I can see the utility of that for some situations (teaching...examples, etc.), it seems like a huge potential for security breaches. Is it possible to have such a function on your site w/o giving access to ALL of your documents... Chip -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#56188) next »