PHP Developers Network

A community of PHP developers offering assistance, advice, discussion, and friendship.
 
Loading
It is currently Thu Oct 17, 2019 6:41 am

All times are UTC - 5 hours




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Wed Nov 23, 2011 6:02 pm 
Offline
Forum Commoner

Joined: Mon Nov 21, 2011 1:16 am
Posts: 69
I'm working on a site where are scripts are loaded through index.php
What is the best way to prevent people from accessing other scripts on the site directly?
I'm currently using something like this:
Syntax: [ Download ] [ Hide ]
if (security_filter($_SERVER['PHP_SELF'],"string") != "/index.php"){ echo "ACCESS DENIED"; exit(); }

Don't worry about security_filter() so basically I'm using:
Syntax: [ Download ] [ Hide ]
if ($_SERVER['PHP_SELF'] != "/index.php"){ echo "ACCESS DENIED"; exit(); }

in every page to prevent people from directly accessing other scripts.


Top
 Profile  
 
PostPosted: Wed Nov 23, 2011 6:57 pm 
Offline
Briney Mod
User avatar

Joined: Mon Jan 19, 2004 7:11 pm
Posts: 6446
Location: 53.01N x 112.48W
Use mod_rewrite to redirect all requests to index.php (except maybe image files & css files). In your index.php file, you can check in $_SERVER what page he person was actually requesting and go from there.

Also, PHP_SELF may not always be set so it's not 100% safe to use. In most cases you can accomplish the same with $_SERVER['SCRIPT_NAME']

_________________
Real programmers don't comment their code. If it was hard to write, it should be hard to understand.


Top
 Profile  
 
PostPosted: Wed Nov 23, 2011 7:02 pm 
Offline
DevNet Resident
User avatar

Joined: Wed Apr 01, 2009 1:31 pm
Posts: 1532
Ideally, you would store sensitive scripts outside the document root so they could not be accessed over HTTP. If your host does not give you access to such a directory, you can put your scripts in a private directory which is password-protected.

Apache HTTP Server:


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group