Php/Apache Ip Security

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • asdasd
    So Fucking Banned
    • Feb 2005
    • 1225

    #1

    Php/Apache Ip Security

    Say I am limiting my includes folder to the localhost like so:

    <Directory "/includes">
    Order allow,deny
    Allow from 192.168.1.0/24
    Allow from 127
    </Directory>

    Would this prevent a php script from including a file in that directory for a web server request?
  • borked
    Totally Borked
    • Feb 2005
    • 6284

    #2
    Nope - php includes don't look at htaccess or any apache directives, since they are file-based. Same goes for php command line script execution.

    For coding work - hit me up on andy // borkedcoder // com
    (consider figuring out the email as test #1)



    All models are wrong, but some are useful. George E.P. Box. p202

    Comment

    • V_RocKs
      Damn Right I Kiss Ass!
      • Nov 2003
      • 32447

      #3
      You are h4x0r3d bitch!

      Comment

      • asdasd
        So Fucking Banned
        • Feb 2005
        • 1225

        #4
        V_RocKs - Preemptive , borked - presumed, thanks.

        Comment

        • Klen
          • Aug 2006
          • 32235

          #5
          Lulz at your question :D

          Comment

          • shake
            frc
            • Jul 2003
            • 4663

            #6
            Unless you use php URL include http://, then it will go through apache and respect htaccess
            Crazy fast VPS for $10 a month. Try with $20 free credit

            Comment

            • asdasd
              So Fucking Banned
              • Feb 2005
              • 1225

              #7
              It's to narrow attack vectors somewhat. Namely to prevent scanning, or bypassing the flow. Way I figure it, I will not have to regard whole directories as exposed, but more simply as referenced.

              Comment

              Working...