note 15388 deleted from function.include by sniper
| From: | sniper@php.net | Date: | Tue, 04 Nov 2003 00:40:31 +0000 |
| Subject: | note 15388 deleted from function.include by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-59775@lists.php.net to get a copy of this message | ||
Note Submitter: <supaplex %at% pcbkits %dot% c0m>
----
My favorite way to avoid remote users from peeking at your include files, is to place them in a
directory named .ht(something). This matches the regexp present in the apache configuration. You
can name files this way to, but it's best to leave a README in the .htblah/ directory to
illistrate your reasoning for a directory named as such. (namley for picky admins)
Apache will match the regexp and issue an error document stating that the resource is off limits.
Enjoy =-)