Re: Keeping "Secrets" in PHP Files
| From: | Tamas Arpad | Date: | Fri, 28 Jun 2002 17:20:51 +0000 |
| Subject: | Re: Keeping "Secrets" in PHP Files | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104373@lists.php.net to get a copy of this message | ||
On Friday 28 June 2002 16:59, Jason Wong wrote:
> On Friday 28 June 2002 22:37, Erik Price wrote:
> > On Friday, June 28, 2002, at 10:11 AM, Jason Wong wrote:
> > > 2) Make sure your 'secret' files are named extremely obscurely as to
> > > be 'unguessable'.
> >
> > It's helpful, but is a kind of "security through obscurity" and won't
> > stop a dedicated cracker.
> >
> >
> > http://www.tuxedo.org/~esr/jargon/html/entry/security-through-
> > obscurity.html
>
> Absolutely. But given the current situation it's better than nothing :)
>
> I was thinking if you use 90 character long filenames, assuming you only
> use the letters of the alphabet and the digits then you would have 62^90
> different filenames, which is roughly 2E161 (2 followed by 161 zeros),
> which is quite a bit. Hopefully the numbers involved would make it
> infeasible for an attacker to loop through all the permutations.
But what if the attacker just knows one file's name, for example index.php
or something that's in the url in the browser. Then he/she can stole that
file, read it, and gets other filenames because of includes/requires.
With some work he/she can get all the files without any bruteforce
filename guessing.
Arpi