Re: PHP Security - "view source code"

From: Date: Thu, 17 Jan 2002 00:05:57 +0000
Subject: Re: PHP Security - "view source code"
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-80858@lists.php.net to get a copy of this message
Apart from unfortunately placed ?> 's or " 's this is possible. A very common mistake is not to register all of your php file extensions with apache. I've seen a number of sites for example that didn't have the .inc extension registered, include() doesn't care about that, but if your includes are under the document root of your website (that happens a lot too, i don't know why ?) and you specify the exact name of the include in your browser (or worse, the directory is browsable from the web), the webserver will default to text/plain content and display the source. Bad thing since includes usually contain passwords and stuff. bvr. On Wed, 16 Jan 2002 13:19:20 -0800, Richard Baskett wrote: >PHP is a server side language so the PHP engine parses all the php code in >your webpage and then spits out html code. So when surfing through a >website that uses PHP you will never see PHP code unless of course you >screwed up and echoed the data :) > >Rick > >"How wonderful it is that nobody need wait a single moment to improve the >world." - Anne Frank > >> From: "Phil Schwarzmann" <pschwar@jhmi.edu> >> Date: Wed, 16 Jan 2002 16:03:45 -0500 >> To: <php-general@lists.php.net> >> Subject: [PHP] PHP Security - "view source code" >> >> How easy/hard is it to view the PHP source code when you're at website? >> >> I noticed when I was using Internet Explorer, if I pressed "view >> source"...it would show the HTML but not the PHP. >> >> -Phil >> > > >-- >PHP General Mailing List (http://www.php.net/) >To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net >For additional commands, e-mail: php-general-help@lists.php.net >To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#80858) next »