Re: Keeping "Secrets" in PHP Files
| From: | Jason Wong | Date: | Fri, 28 Jun 2002 14:59:01 +0000 |
| Subject: | Re: Keeping "Secrets" in PHP Files | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104341@lists.php.net to get a copy of this message | ||
On Friday 28 June 2002 22:37, Erik Price wrote:
> On Friday, June 28, 2002, at 10:11 AM, Jason Wong wrote:
> > 2) Make sure your 'secret' files are named extremely obscurely as to be
> > 'unguessable'.
>
> It's helpful, but is a kind of "security through obscurity" and won't
> stop a dedicated cracker.
>
> http://www.tuxedo.org/~esr/jargon/html/entry/security-through-
> obscurity.html
Absolutely. But given the current situation it's better than nothing :)
I was thinking if you use 90 character long filenames, assuming you only use
the letters of the alphabet and the digits then you would have 62^90
different filenames, which is roughly 2E161 (2 followed by 161 zeros), which
is quite a bit. Hopefully the numbers involved would make it infeasible for
an attacker to loop through all the permutations.
<?
echo time() . "\n";
for ($i = 1; $i <= 1000000; $i++) {
}
echo time() . "\n";
?>
FWIW this empty loop takes 4 seconds to execute on a 300MHz Celeron system.
--
Jason Wong -> Gremlins Associates -> www.gremlins.com.hk
Open Source Software Systems Integrators
* Web Design & Hosting * Internet & Intranet Applications Development *
/*
Where will it all end? Probably somewhere near where it all began.
*/