Re: Keeping "Secrets" in PHP Files

From: Date: Fri, 28 Jun 2002 14:59:01 +0000
Subject: Re: Keeping "Secrets" in PHP Files
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-104341@lists.php.net to get a copy of this message
On Friday 28 June 2002 22:37, Erik Price wrote: > On Friday, June 28, 2002, at 10:11 AM, Jason Wong wrote: > > 2) Make sure your 'secret' files are named extremely obscurely as to be > > 'unguessable'. > > It's helpful, but is a kind of "security through obscurity" and won't > stop a dedicated cracker. > > http://www.tuxedo.org/~esr/jargon/html/entry/security-through- > obscurity.html Absolutely. But given the current situation it's better than nothing :) I was thinking if you use 90 character long filenames, assuming you only use the letters of the alphabet and the digits then you would have 62^90 different filenames, which is roughly 2E161 (2 followed by 161 zeros), which is quite a bit. Hopefully the numbers involved would make it infeasible for an attacker to loop through all the permutations. <? echo time() . "\n"; for ($i = 1; $i <= 1000000; $i++) { } echo time() . "\n"; ?> FWIW this empty loop takes 4 seconds to execute on a 300MHz Celeron system. -- Jason Wong -> Gremlins Associates -> www.gremlins.com.hk Open Source Software Systems Integrators * Web Design & Hosting * Internet & Intranet Applications Development * /* Where will it all end? Probably somewhere near where it all began. */

« previous php.general (#104341) next »