RE: [PHP] hacks we should know about

From: Date: Tue, 21 Aug 2001 17:25:08 +0000
Subject: RE: [PHP] hacks we should know about
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-63741@lists.php.net to get a copy of this message
I don't host my own site so how can I put include files outside of the web root? I log on ftp and my top level IS the web root (htdocs), I can't go any higher. - seb -----Original Message----- From: Rasmus Lerdorf [mailto:rasmus@php.net] Sent: 17 August 2001 05:01 To: Bob Cc: php-general@lists.php.net Subject: Re: [PHP] hacks we should know about > hi i found it very helpful to know about hacks such as the below list > and was wondering if anyone had any more dumb mistakes they could tell > us before we make them. > > 1. http://www.somesite.com/source.php3?url=/etc/passwd > 2. http://www.somesite.com?page=../../../../etc/passwd > 3. not setting .inc files to be parsed by php This is the wrong solution to securing include files. The correct solution is to block any direct access to .inc files by either putting them outside your document root or by using an Apache deny rule. -Rasmus -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#63741) next »