Re: PHP Security - "view source code"

From: Date: Thu, 17 Jan 2002 01:04:40 +0000
Subject: Re: PHP Security - "view source code"
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-80863@lists.php.net to get a copy of this message
> On Thu, 17 Jan 2002, bvr@xs4all.nl wrote: > > > I've seen a number of sites for example that didn't have the .inc extension > > registered, > > include() doesn't care about that, but if your includes are under the document root > > of your > > website (that happens a lot too, i don't know why ?) and you specify the exact name > > of > > the include in your browser (or worse, the directory is browsable from the web), the > > webserver > > will default to text/plain content and display the source. Bad thing since includes > > usually contain > > passwords and stuff. > > I agree with this, since I saw such mistakes wit my own eyes. IMHO, the > best way to avoid this kind of problems is to: > > (1) avoid using .inc files; use .php files like for normal script No, it is safer to block access to .inc files with an httpd.conf rule. Allowing people to execute files that were meant to be included out of context could end up being much more dangerous than simply having people see the source. -Rasmus

« previous php.general (#80863) next »