note 35908 added to security
| From: | Dave at rn2 dot php dot net | Date: | Thu, 18 Sep 2003 19:13:18 +0000 |
| Subject: | note 35908 added to security | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-56723@lists.php.net to get a copy of this message | ||
Another way to stop a user from looking at or executing the files read by include() or require() is
to use a different file extension for them (i.e. *.inc) and add the following to your apache
configuration:
<Files ~ "\.inc$">
Order allow,deny
Deny from all
Satisfy All
</Files>
They won't execute unless used in a include() or require() since they don't have the *.php
extension, and the server won't serve them up as text/plain with the directive above.
----
Manual Page -- http://www.php.net/manual/en/security.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+35908
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+35908&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+35908&report=yes