Re: virtual() call to CGI script
| From: | Egan | Date: | Tue, 28 Aug 2001 14:01:08 +0000 |
| Subject: | Re: virtual() call to CGI script | ||
| References: | 1 2 3 4 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-64797@lists.php.net to get a copy of this message | ||
On Tue, 28 Aug 2001 23:38:30 +1000, "Jason Brooke" <jb@qgl.org> wrote:
>if you're using apache, something along the lines of the following untested
>directives should prevent anyone but the localhost (which is where your
>virtual() calls should be coming from) from accessing the cgi's via http
>
><Directory /path/to/usr/cgi>
>order deny, allow
>deny from all
>allow from localhost
></Directory>
We don't define any virtual hosts in httpd.conf; instead, we use a
custom handler hooked into post-read-request. So I won't be able to
define "/path/to/usr/cgi" in httpd.conf.
But if that concept will work in user .htaccess files, it would be an
improvement over my current techniques. I'll give it a try ...
Thanks for the idea!
Egan