note 32524 deleted from function.include by sniper
| From: | sniper@php.net | Date: | Tue, 04 Nov 2003 00:42:03 +0000 |
| Subject: | note 32524 deleted from function.include by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-59790@lists.php.net to get a copy of this message | ||
Note Submitter: php@cain.sh
----
Here is one way to expand on the above method to prevent
browsers direct access to supporting "include" scripts. If possible you
should IMHO keep your include/require files in a directory outside the web
content directories. But being that isn't always an option you can copy the
code below to the begining of any scripts you need to prevent direct
access to. It should figure out the rest regardless of where the protected
script gets moved or renamed to.
<?php
// This will only be true if the page is accessed directly
if( strpos(__FILE__, $_SERVER['PHP_SELF']) !== FALSE ) {
// Determine the protocol based on the standard ports
switch($_SERVER['SERVER_PORT']) {
case '80':
$protocol = 'http:'; // Ignore the hyperlink
that is created here ;)
break;
case '443':
$protocol = 'https:';
break;
default:
$protocol = '';
}
// Create the header to send them away
$header = 'Location: '.$protocol.'//'.$_SERVER['HTTP_HOST'];
// Add on to the header to send them back to the site in the same
// directory as this file. So /some/dir/include.php would send them
// back to /some/dir/include.php.
//
// Note: Change this to a bad_guy.php page if you like
$header.= str_replace(basename(__FILE__), '', $_SERVER['PHP_SELF']);
// Make them go away
header($header);
// Terminate the script in case they don't listen to the header (spiders
// and such).
exit();
}
?>
Hope this helps someone out there.
-Dan
:wq