English 中文(简体)
PHP: 是使用指数.php作为boot?
原标题:PHP: Is it secure to use index.php as the bootstrap?

我要问的是,这似乎只是一个适当的指数所要求的。 营地档案是“on子”文件。 我假定这增加了一个安全层面,但如果不是,这种模式似乎毫无意义。 为什么不只使用指数。 php是boot的陷阱? 任何意见、警告、思想等都受到赞赏!

(以这种方式,我的单人查阅文件将所有要求都转至索引。) php file...

最佳回答

不存在内在的安全差别,无论你在指数档案中是否有boot,还是单独填写。

单独档案通常由于组织的关切(例如,从其他地方可以列入档案,以进口贵方的供述职能,或将所有任务放在适当名称的档案中,或特别容易将习俗延伸到boot过程)。

然而,组合<>包含敏感信息的文档——有时,除索引档案外,更很少,甚至所有PHP文件——将尽可能放在网络内。 <will使PHP文档在出现意外服务器故障时无法从外部查阅安全方面有所变化。

问题回答

a 仅为指数。 网址是文件根基,其他所有PHP文档都应在文件根基之外,因此,当指数时,就具有意义。 营地档案只包括文件根基以外的一个诱杀装置。

我不知道这种脆弱性。 编制空白索引.html或索引。 如果混淆了一谈,则把营地编成一个夹子,就可以防止攻击者获得一张目录。





相关问题
Signed executables under Linux

For security reasons, it is desirable to check the integrity of code before execution, avoiding tampered software by an attacker. So, my question is How to sign executable code and run only trusted ...

MALICIOUS_CODE EI_EXPOSE_REP Medium

I run findbugs against all of my code and only tackle the top stuff. I finally got the top stuff resolved and now am looking at the details. I have a simple entity, say a user: public class User ...

XSS on jsbin.com

Anyone know if jsbin.com implements any protection for XSS or other javascript attacks? I see jsbin links used fairly regularly on sites like this one and I can t find any indication from the site ...

Make md5 strong

Im making a website that will intergrate with game that only support md5 hashing metod (atm). Which ofc is not especially safe anymore. But how could i make it stronger? Should I just generate long ...

Why running a service as Local System is bad on windows?

I am trying to find out the difference between difference service account types. I tumbled upon this question. The answer was because it has powerful access to local resources, and Network Service ...

Brute-force/DoS prevention in PHP [closed]

I am trying to write a script to prevent brute-force login attempts in a website I m building. The logic goes something like this: User sends login information. Check if username and password is ...

热门标签