RE: [PHP] Re: how to hide dbconnect file if its in published dire ctory?
| From: | Chadwick, Russell | Date: | Mon, 09 Jul 2001 22:46:03 +0000 |
| Subject: | RE: [PHP] Re: how to hide dbconnect file if its in published dire ctory? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-57029@lists.php.net to get a copy of this message | ||
Have the script dump the envoirnment vars to a file and compare the
variables from a user vs include because some of those variables apache gets
from a browser, off the top of my head REMOTE_ADDR should work, that wont be
set when you include. So just die() if its set. - Russ
-----Original Message-----
From: James, Yz [mailto:liljim@btconnect.com]
Sent: Monday, July 09, 2001 4:00 PM
To: php-general@lists.php.net
Subject: [PHP] Re: how to hide dbconnect file if its in published
directory?
Hi Noah,
if you make the include file a .php file, then the browser will parse the
code as a blank page.... whether or not they choose to look at the file, or
try to fopen(etc) it......... Problem solved ;) At least I think that's
safe-ish...
James.
"Noah Spitzer-Williams" <noahsw@cyberdude.com> wrote in message
news:20010709221128.19007.qmail@pb1.pair.com...
> Hey guys,
>
> I come for advice once again. Say i have a file dbconnect.inc which
> connects to my database. Now if this file is located in a directory
> accessible for to the web is there anyway that if someone types in that
file
> i can detect it being accessed, instead of included, and redirect them
> elsewhere?
>
> Thanks guys!
>
> - Noah
>
>
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net