Re: PHP Security - "view source code"
| From: | Erik Price | Date: | Thu, 17 Jan 2002 16:34:46 +0000 |
| Subject: | Re: PHP Security - "view source code" | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-80927@lists.php.net to get a copy of this message | ||
On Wednesday, January 16, 2002, at 08:04 PM, Rasmus Lerdorf wrote:
No, it is safer to block access to .inc files with an httpd.conf rule. Allowing people to execute files that were meant to be included out of context could end up being much more dangerous than simply having people see the source. -RasmusSo the technique of adding ".inc" to the list of extensions in "AddType application/x-httpd-php" line and just having PHP parse them as PHP code is unwise? Or should a combination of the two be used -- parsing ".inc" files *AND* blocking access to them in httpd.conf? Erik