NYCPHP Meetup

[nycphp-talk] htaccess & php

Michele Waldman mmwaldman at nyc.rr.com
Fri Nov 28 15:26:10 EST 2008


I'm getting closer.

 

RewriteCond %{HTTP_REFERER} !^http://(.+\.)?mydomain\.com/ [NC]

RewriteCond %{HTTP_REFERER} !^$

RewriteRule .*\.(jpe?g|gif|bmp|png)$ /img/nolink.jpg [L]

RewriteRule .type1(.+)?\.php(.+)?$ stub.php [L]

RewriteRule .file1\.php(.+)?$ stub.php [L]

 

These rules prevent my domain from calling the modules.

 

The html uses    src="../../type1.php?arg1=blah" and

                        Src="../../file1.php"

 

I want my code and my code only to be able to use these modules.

 

Michele

 

  _____  

From: talk-bounces at lists.nyphp.org [mailto:talk-bounces at lists.nyphp.org] On
Behalf Of Michele Waldman
Sent: Friday, November 28, 2008 3:03 PM
To: 'NYPHP Talk'
Subject: [nycphp-talk] htaccess & php

 

This is not working for me

 

RewriteCond %{HTTP_REFERER} !^http://(.+\.)?mydomain\.com/ [NC]

RewriteCond %{HTTP_REFERER} !^$

RewriteRule .*\.(jpe?g|gif|bmp|png)$ /image/nolink.jpg [L]

RewriteRule .file1\.php(\?*)?$ stub.php [L]

RewriteRule .type1_*\.php(\?*)?$ stub.php [L]

 

All of the php files are referred to in the html as:

 

Src="../../file1.php"  or

 

Src="../../type1_file2.php?arg1=blah

 

In the case of file1, I'm just getting the stub.php

 

In the case of type1_file2.php the file is being call.  I think because my
string didn't match.

 

I'm trying to lock out remote call to the php files.

 

Michele

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.nyphp.org/pipermail/talk/attachments/20081128/c105eb91/attachment.html>


More information about the talk mailing list