Re: include, chmod, password files

From: Date: Wed, 08 Aug 2001 18:16:15 +0000
Subject: Re: include, chmod, password files
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-61881@lists.php.net to get a copy of this message
On Wed, 8 Aug 2001 12:03:34 -0600 "Johnson, Kirk" <kjohnson@zootweb.com> wrote: > > If I have a file called db.inc with, for example, this: > > > > However, any user on the system can read db.inc cause its > > chmod'd 0644. > > If I chmod db.inc 0600 or even 0640, index.php can not include it. > > > > How do I go about protecting my files from being read by > > users on the system? > > Below is how Rasmus recommends this be handled. > > Kirk > > The right way to fix this is to add a rule to your Apache configuration > that looks like this: > > <Files ~ "\.inc$"> > Order allow,deny > Deny from all > </Files> > > That will simply prevent any direct access at all to your .inc files. > Making the .inc files simply be parsed by PHP could still be a problem as > they could be called out of context. > > -Rasmus > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > This is not what I was asking... I mean a user on the local system cd /home/david/webpage/include cat db.inc he can read my db.inc. - David

« previous php.general (#61881) next »