4 ms·
Did you remove all the code pages? Otherwise, an attacker is not restricted to following links on your site, they can access the code urls directly?
by ifdefdebug 5y ago
Did you remove all the code pages? Otherwise, an attacker is not restricted to following links on your site, they can access the code urls directly?
- Tomte 5y agoNo, they can't. As I said, the nginx or Apache configuration makes sure. Look it up, you're routing everything to static files in file system directories. Only if you are requesting an URL (however "you" are identified) the webserver even contemplates serving something else. It's an explicit rule for the special case. Everyone else doesn't see a PHP-FPM execution path at all.