Re: PHP Security - "view source code"

From: Date: Thu, 17 Jan 2002 01:21:44 +0000
Subject: Re: PHP Security - "view source code"
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-80864@lists.php.net to get a copy of this message
> > (1) avoid using .inc files; use .php files like for normal script > > No, it is safer to block access to .inc files with an httpd.conf rule. The way I approach this, besides blocking execution, is to put any sensitive files in a directory above the Document Root for the virtual domain. PHP can then reach it, but Apache won't. /var/www/domain.name /var/www/domain.name/htdocs <-- php scripts go here /var/www/domain.name/private <-- inc files go here Billy

« previous php.general (#80864) next »