Re: Keeping "Secrets" in PHP Files

From: Date: Fri, 28 Jun 2002 17:20:51 +0000
Subject: Re: Keeping "Secrets" in PHP Files
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-104373@lists.php.net to get a copy of this message
On Friday 28 June 2002 16:59, Jason Wong wrote: > On Friday 28 June 2002 22:37, Erik Price wrote: > > On Friday, June 28, 2002, at 10:11 AM, Jason Wong wrote: > > > 2) Make sure your 'secret' files are named extremely obscurely as to > > > be 'unguessable'. > > > > It's helpful, but is a kind of "security through obscurity" and won't > > stop a dedicated cracker. > > > > > > http://www.tuxedo.org/~esr/jargon/html/entry/security-through- > > obscurity.html > > Absolutely. But given the current situation it's better than nothing :) > > I was thinking if you use 90 character long filenames, assuming you only > use the letters of the alphabet and the digits then you would have 62^90 > different filenames, which is roughly 2E161 (2 followed by 161 zeros), > which is quite a bit. Hopefully the numbers involved would make it > infeasible for an attacker to loop through all the permutations. But what if the attacker just knows one file's name, for example index.php or something that's in the url in the browser. Then he/she can stole that file, read it, and gets other filenames because of includes/requires. With some work he/she can get all the files without any bruteforce filename guessing. Arpi

« previous php.general (#104373) next »