    alternate security meathod needed .htaccess / php

    previously had prevented certain pages from being viewed in htaccess files by listing the .html names of the files (FilesMatch) w/ domain/IP restrictions.

    The web page has been converted to php and now has and index.php file that is always displayed with the differing content piped in by opening the original html files. So pages are differentiated as follows index.php?content = value3. In the scripting portion the valuex portion dirrects which html file to open.

    The problem with doing it this was is that the html files that were previously restricted are no longer. Is there a way to restore the original security features .htaccess or not?

    Jan 2001
    throw the html files in a directory with htpasswd
    eeeeeeeeeeeeeeeewwwww it's broke

    Apr 2002
    You would need to do this filtering in the index.php PHP script.

    You might be able to do it with mod_rewrite in your .htaccess file, but I cannot be certain if this can be accomplished.

    Sep 2009
    htpassword should be good.

    Jun 2007
    If you need to allow certain HTML files via index.php and restrict the other, it is more secure doing it within index.php itself. Since index.php is exposed to directory traversal vulneraibility i.e. index.php?content=../../../../../../etc/passwd%%00

