Re: PHP Security - "view source code"
| From: | mike cullerton | Date: | Thu, 17 Jan 2002 04:25:31 +0000 |
| Subject: | Re: PHP Security - "view source code" | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-80873@lists.php.net to get a copy of this message | ||
on 1/16/02 6:04 PM, Rasmus Lerdorf at rasmus@lerdorf.ca wrote:
>> On Thu, 17 Jan 2002, bvr@xs4all.nl wrote:
>>
>> (1) avoid using .inc files; use .php files like for normal script
>
> No, it is safer to block access to .inc files with an httpd.conf rule.
> Allowing people to execute files that were meant to be included out of
> context could end up being much more dangerous than simply having people
> see the source.
here is that httpd.conf rule stolen from an earlier post by Rasmus
<Files ~ "\.inc$">
Order allow,deny
Deny from all
</Files>
with this rule, if someone requests a file ending in .inc, apache won't
deliver it. however, php will still be allowed to include those files
itself.
-- mike cullerton michaelc at cullerton dot com