note 24373 added to security.registerglobals

From: Date: Wed, 14 Aug 2002 15:45:01 +0000
Subject: note 24373 added to security.registerglobals
Groups: php.notes 
Request: Send a blank email to php-notes+get-35002@lists.php.net to get a copy of this message
Para proteger la seguridad de tu web, y forzar una navegacion segura, siguiendo los links de la web, y impedir las demas peticiones, esto puede ser una solucion: 1º.pones en la configuracion de apache lo siguiente, para que no puedan usar tus ficheros remotamente. **** SetEnvIfNoCase Referer "^http://www.mysite.com/" local_ref=1 <FilesMatch ".(gif|jpg|png|html|xox)"> Order Allow,Deny Allow from env=local_ref </FilesMatch> **** y ademas cambias la extension .php por .xox o cualquier otra, en todos los scripts, menos en el index.php. **** AddType application/x-httpd-php .php .php4 .php3 .phtml .xox **** Con esto se obliga al usuario a seguir los links de la pagina web, y no se le permite hacer peticiones directas desde el navegador o desde una shell. -- http://www.php.net/manual/en/security.registerglobals.php http://master.php.net/manage/user-notes.php?action=edit+24373 http://master.php.net/manage/user-notes.php?action=delete+24373 http://master.php.net/manage/user-notes.php?action=reject+24373

« previous php.notes (#35002) next »