Re: Keeping "Secrets" in PHP Files

From: Date: Fri, 28 Jun 2002 14:11:05 +0000
Subject: Re: Keeping "Secrets" in PHP Files
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-104333@lists.php.net to get a copy of this message
On Friday 28 June 2002 21:51, Jonathan Rosenberg wrote: > Thanks for the reply. But changing the ground read permission of > the PHP files wouldn't help, either, would it? Because the other > users who have web sites can just create a PHP file that reads my > PHP files from one of their pages (which would be running in > group "websecret"). > > Seems like this just opens up the same hole. Yes? You can try the following: 1) Make a directory under your web docroot where all your 'secret' files can be kept. 2) Make sure your 'secret' files are named extremely obscurely as to be 'unguessable'. 3) Then "chmod ugo-r" your 'secret' directory. This prevents the directory contents from being listed, thus unless people know the names of your secret files they won't be able to access them. -- Jason Wong -> Gremlins Associates -> www.gremlins.com.hk Open Source Software Systems Integrators * Web Design & Hosting * Internet & Intranet Applications Development * /* This sentence does in fact not have the property it claims not to have. */

« previous php.general (#104333) next »