![]() |
Security: Denying direct access to files
I'd like to deny access to the include files - I know that vB tries to do this , but I'd like to do it explicitly. Other than /include/ , are there any dirs that can be denied?
|
I believe /clientscript/ is as well :)
Satan |
Lol, denying clientscript, will make the board not function anymore i guess.
|
Quote:
Serriously though.. the includes directiory doesn't contain anything that can harm your board from direct web access. |
well a good way to prevent a file from being called by itsel:
I believe this would work: Code:
if (eregi("filename.php",$_SERVER['PHP_SELF'])) { |
just htaccess the directory if your worried...
|
The only directory that can be locked out is includes.
|
All scripts that are not ment to be called directly, are already "protected" against starting them directly, or at least protected from performing any actions.
|
The easy way to do this:
<Files *.php> Order allow,deny Deny from all </Files> <Files *.extension1> Order allow,deny Deny from all </Files> <Files *.anotherextension> Order allow,deny Deny from all </Files> Put this into .htaccess of every folder you want to protect. |
You know what I meant :p
I mean users cannot harm the board by accessing them directly:p I misunderstood what he was asking and thought he wanted to know what directories were protected from damaging the board by users typing the url in :p Satan |
All times are GMT. The time now is 09:13 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|