Re: Keeping "Secrets" in PHP Files

From: Date: Fri, 28 Jun 2002 17:57:37 +0000
Subject: Re: Keeping "Secrets" in PHP Files
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-104394@lists.php.net to get a copy of this message
On Saturday 29 June 2002 01:20, Tamas Arpad wrote: > But what if the attacker just knows one file's name, for example index.php > or something that's in the url in the browser. Then he/she can stole that > file, read it, and gets other filenames because of includes/requires. > With some work he/she can get all the files without any bruteforce > filename guessing. Good point :) -- Jason Wong -> Gremlins Associates -> www.gremlins.com.hk Open Source Software Systems Integrators * Web Design & Hosting * Internet & Intranet Applications Development * /* "Facts are stupid things." -- President Ronald Reagan (a blooper from his speeach at the '88 GOP convention) */

« previous php.general (#104394) next »