Re: Security of PHP code
| From: | Tyrone Mills | Date: | Wed, 04 Jul 2001 16:14:30 +0000 |
| Subject: | Re: Security of PHP code | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-56190@lists.php.net to get a copy of this message | ||
I use something that accomplishes the same (displays the source of a file),
but doesn't accept the file name as a parameter. The script is also in a
directory with a password and is restricted by ip. Not perfect, but alot
better.
----- Original Message -----
From: "Hankley, Chip" <Chip.Hankley@GASAI.Com>
To: "PHP Mailingliste" <php-general@lists.php.net>
Sent: Wednesday, July 04, 2001 8:45 AM
Subject: RE: [PHP] Security of PHP code
> OK,
>
> I'm pretty new to PHP, and have been reading this thread, and am just a
> little freaked.
>
> If I understand this right, the only way reason we can view the source
code
> of those pages is that the web server on which the page resides
essentially
> has a PHP page somewhere on their site that has some variation of:
>
> <?show_source($file);?>
>
> as it's content, right?
>
> While I can see the utility of that for some situations
> (teaching...examples, etc.), it seems like a huge potential for security
> breaches.
>
> Is it possible to have such a function on your site w/o giving access to
ALL
> of your documents...
>
> Chip
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>