Graphic Design Forum and Web Design Forum  

Go Back   Graphic Design Forum and Web Design Forum »Web Design Forum »Programming Forum

Notices

Programming Forum Web and Software Programming Forum - Java, PHP, SQL etc.


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-04-2008, 05:06 PM
skunkbad's Avatar
Junior Member
 
Join Date: Apr 2008
Location: Temecula, California, USA
Posts: 40
Default PHP fopen() security issue

One of the websites that I maintain is on a server where I can fopen() and fread() anything on the server. There are a few hundred websites on there, and I don't believe I should have access to go into them, but I wanted to test so that I could improve my own security. "fopening" these files reveals ALL code, even preprocessed php code / asp code. Is there a way that I can protect the site I am working on from other people "fopening"? Server is a windows server with IIS. I can't use .ini files or .htaccess files, so I'm not sure I can do anything without contacting the host... Maybe I just need to change hosts. I don't like being on a windows server, but I inherited the site, and would rather not have to deal with the move.
__________________
Brian's Web Design - Temecula
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!RSS Share on Facebook Share This Article & VoteForum Netvibes Page
Reply With Quote
  #2 (permalink)  
Old 10-04-2008, 07:03 PM
flick's Avatar
resident geek
 
Join Date: Aug 2007
Location: Manchester
Posts: 1,772
Default

you can't use .htaccess files with iis but you can use .ini files, alternatively you could install apache on the server so you wouldn't have to move hosting, would be alot of work though depending on how many sites you have on the server :)
__________________
-- my new favourite g33k site: http://parsed.org --
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!RSS Share on Facebook Share This Article & VoteForum Netvibes Page
Reply With Quote
  #3 (permalink)  
Old 10-04-2008, 07:07 PM
skunkbad's Avatar
Junior Member
 
Join Date: Apr 2008
Location: Temecula, California, USA
Posts: 40
Default

Quote:
Originally Posted by flick View Post
you can't use .htaccess files with iis but you can use .ini files, alternatively you could install apache on the server so you wouldn't have to move hosting, would be alot of work though depending on how many sites you have on the server :)
So what would I put in a php.ini file to stop other people from fopening my files?. This is a shared hosting account, so I don't have the option of installing Apache.
__________________
Brian's Web Design - Temecula
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!RSS Share on Facebook Share This Article & VoteForum Netvibes Page
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Company Logo flick Graphic Design & Web Design Critique 5 04-02-2008 02:49 AM
Mac users 'still lax on security' Toon Apple Mac Forum 2 20-02-2007 07:07 PM
Microsoft fixes 20 security holes Toon PC Forum 0 15-02-2007 10:48 AM
Display Issue and Nav Loading Issue tschneider Graphic Design and Web Design Help 12 23-01-2007 09:34 PM
Reader Security Risk Toon Design and Print Software 0 05-01-2007 02:47 PM


All times are GMT. The time now is 07:49 AM.



Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0 RC5