homepage Welcome to WebmasterWorld Guest from 54.167.75.155
register, free tools, login, search, pro membership, help, library, announcements, recent posts, open posts,
Become a Pro Member

Home / Forums Index / Hardware and OS Related Technologies / Website Technology Issues
Forum Library, Charter, Moderators: phranque

Website Technology Issues Forum

    
locking down file access in a shared env
Nuttzy99




msg:660571
 7:46 pm on Aug 28, 2003 (gmt 0)

Hello WebmasterWorld ;)

I want to store a key in a file and keep it protected. I don't wish to password protect it b/c it is assumed that users on the shared server will already have access to the DB info and there is no way of getting around that.

What should do the trick is a .htaccess file that can reject users coming from anywhere but a specific URL like [mysite.com...] Unfortunately I'm a n00b when it comes to .htaccess. Is this possible?

FYI, a 700 directory owned by the webserver will be created and the file with the key placed within. This will lock out any users other than the webserver. The purpose of the .htaccess will be to stop the clever folks that know to simply fopen in PHP to look at anything owned by the webserver. The sensitive code in access.php is already locked down.

Thank you!
-Nuttzy ;)

p.s. I strongly recommend using phpBB for forum software, but I'm biased :p

 

DaveAtIFG




msg:660572
 2:08 am on Sep 1, 2003 (gmt 0)

Welcome to WebmasterWorld Nuttzy99! :)

This thread [webmasterworld.com] will get you started I think. Pay attention to the <Limit GET> suggestions since I think this approach will do the job for you.

Also, check out Apache's .htaccess howto [httpd.apache.org] and specifics on all of the Apache directives is here [httpd.apache.org].

Post your solution and our regulars are usually happy to help you debug it!

Global Options:
 top home search open messages active posts  
 

Home / Forums Index / Hardware and OS Related Technologies / Website Technology Issues
rss feed

All trademarks and copyrights held by respective owners. Member comments are owned by the poster.
Home ¦ Free Tools ¦ Terms of Service ¦ Privacy Policy ¦ Report Problem ¦ About ¦ Library ¦ Newsletter
WebmasterWorld is a Developer Shed Community owned by Jim Boykin.
© Webmaster World 1996-2014 all rights reserved