RE: [PHP] hacks we should know about
| From: | Seb Frost | Date: | Tue, 21 Aug 2001 17:25:08 +0000 |
| Subject: | RE: [PHP] hacks we should know about | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-63741@lists.php.net to get a copy of this message | ||
I don't host my own site so how can I put include files outside of the web
root? I log on ftp and my top level IS the web root (htdocs), I can't go
any higher.
- seb
-----Original Message-----
From: Rasmus Lerdorf [mailto:rasmus@php.net]
Sent: 17 August 2001 05:01
To: Bob
Cc: php-general@lists.php.net
Subject: Re: [PHP] hacks we should know about
> hi i found it very helpful to know about hacks such as the below list
> and was wondering if anyone had any more dumb mistakes they could tell
> us before we make them.
>
> 1. http://www.somesite.com/source.php3?url=/etc/passwd
> 2. http://www.somesite.com?page=../../../../etc/passwd
> 3. not setting .inc files to be parsed by php
This is the wrong solution to securing include files. The correct
solution is to block any direct access to .inc files by either putting
them outside your document root or by using an Apache deny rule.
-Rasmus
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net