Re: PHP Security - "view source code"
| From: | Billy Harvey | Date: | Thu, 17 Jan 2002 01:21:44 +0000 |
| Subject: | Re: PHP Security - "view source code" | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-80864@lists.php.net to get a copy of this message | ||
> > (1) avoid using .inc files; use .php files like for normal script
>
> No, it is safer to block access to .inc files with an httpd.conf rule.
The way I approach this, besides blocking execution, is to put any
sensitive files in a directory above the Document Root for the virtual
domain. PHP can then reach it, but Apache won't.
/var/www/domain.name
/var/www/domain.name/htdocs <-- php scripts go here
/var/www/domain.name/private <-- inc files go here
Billy