note 35908 deleted from security by aidan
| From: | aidan@php.net | Date: | Tue, 07 Sep 2004 23:33:19 +0000 |
| Subject: | note 35908 deleted from security by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-76184@lists.php.net to get a copy of this message | ||
Note Submitter: Dave Mink
----
Another way to stop a user from looking at or executing the files read by include() or require() is
to use a different file extension for them (i.e. *.inc) and add the following to your apache
configuration:
<Files ~ "\.inc$">
Order allow,deny
Deny from all
Satisfy All
</Files>
They won't execute unless used in a include() or require() since they don't have the *.php
extension, and the server won't serve them up as text/plain with the directive above.