Re: how to hide dbconnect file if its in published directory?
| From: | David Robley | Date: | Tue, 10 Jul 2001 00:59:38 +0000 |
| Subject: | Re: how to hide dbconnect file if its in published directory? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-57045@lists.php.net to get a copy of this message | ||
On Thu, 1 Jan 1970 09:30, olsonric@otn.net wrote:
> > I come for advice once again. Say i have a file dbconnect.inc
> > which connects to my database. Now if this file is located in a
> > directory accessible for to the web is there anyway that if someone
> > types in that file i can detect it being accessed, instead of
> > included, and redirect them elsewhere?
> >
> >Thanks guys!
> >
> >- Noah
>
> Sure, try putting a quick if statement at the top checking for the
> $PHP_SELF. If it's dbconnect.inc, then have it die with a message...
>
> if($PHP_SELF == 'dbconnect.inc') { die{"Access Denied!"); }
>
> Also, I know that my server isn't set to parse .inc files, and it shows
> the source of them. For that reason, I renamed all my include files to
> .php.
>
> rick
> http://techno-weenie.com
Of course, if your server has the capability, you could always set it not
to serve .inc files.
Apache:
# Keep from serving .inc files anywhere in the DocumentRoot structure
<LocationMatch ".*\.inc$">
Order allow,deny
Deny from all
</LocationMatch>
--
David Robley Techno-JoaT, Web Maintainer, Mail List Admin, etc
CENTRE FOR INJURY STUDIES Flinders University, SOUTH AUSTRALIA
Oxymoron: Safe Sex.