Re: include, chmod, password files
| From: | David Hill | Date: | Wed, 08 Aug 2001 18:16:15 +0000 |
| Subject: | Re: include, chmod, password files | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-61881@lists.php.net to get a copy of this message | ||
On Wed, 8 Aug 2001 12:03:34 -0600
"Johnson, Kirk" <kjohnson@zootweb.com> wrote:
> > If I have a file called db.inc with, for example, this:
> >
> > However, any user on the system can read db.inc cause its
> > chmod'd 0644.
> > If I chmod db.inc 0600 or even 0640, index.php can not include it.
> >
> > How do I go about protecting my files from being read by
> > users on the system?
>
> Below is how Rasmus recommends this be handled.
>
> Kirk
>
> The right way to fix this is to add a rule to your Apache configuration
> that looks like this:
>
> <Files ~ "\.inc$">
> Order allow,deny
> Deny from all
> </Files>
>
> That will simply prevent any direct access at all to your .inc files.
> Making the .inc files simply be parsed by PHP could still be a problem as
> they could be called out of context.
>
> -Rasmus
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
This is not what I was asking...
I mean a user on the local system
cd /home/david/webpage/include
cat db.inc
he can read my db.inc.
- David