note 32524 deleted from function.include by sniper

From: Date: Tue, 04 Nov 2003 00:42:03 +0000
Subject: note 32524 deleted from function.include by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-59790@lists.php.net to get a copy of this message
Note Submitter: php@cain.sh ---- Here is one way to expand on the above method to prevent browsers direct access to supporting "include" scripts. If possible you should IMHO keep your include/require files in a directory outside the web content directories. But being that isn't always an option you can copy the code below to the begining of any scripts you need to prevent direct access to. It should figure out the rest regardless of where the protected script gets moved or renamed to. <?php // This will only be true if the page is accessed directly if( strpos(__FILE__, $_SERVER['PHP_SELF']) !== FALSE ) { // Determine the protocol based on the standard ports switch($_SERVER['SERVER_PORT']) { case '80': $protocol = 'http:'; // Ignore the hyperlink that is created here ;) break; case '443': $protocol = 'https:'; break; default: $protocol = ''; } // Create the header to send them away $header = 'Location: '.$protocol.'//'.$_SERVER['HTTP_HOST']; // Add on to the header to send them back to the site in the same // directory as this file. So /some/dir/include.php would send them // back to /some/dir/include.php. // // Note: Change this to a bad_guy.php page if you like $header.= str_replace(basename(__FILE__), '', $_SERVER['PHP_SELF']); // Make them go away header($header); // Terminate the script in case they don't listen to the header (spiders // and such). exit(); } ?> Hope this helps someone out there. -Dan :wq

« previous php.notes (#59790) next »