Re: Keeping "Secrets" in PHP Files

From: Date: Fri, 28 Jun 2002 18:04:30 +0000
Subject: Re: Keeping "Secrets" in PHP Files
References: 1 2 3 4  Groups: php.general 
Request: Send a blank email to php-general+get-104396@lists.php.net to get a copy of this message
Remember this..."if a hacker really wants in, then he/she will get in". We just need to do our best to try and prevent it on our systems. Also remember that most companies (people) have plans for compromised systems. This might be something to look at... The only 100% hack proof system is one that is not connected to the internet. If 100% secure is what you want unplug your computer. B i g D o g ----- Original Message ----- From: "Jason Wong" <php-general@gremlins.com.hk> To: <php-general@lists.php.net> Sent: Friday, June 28, 2002 11:57 AM Subject: Re: [PHP] Keeping "Secrets" in PHP Files > On Saturday 29 June 2002 01:20, Tamas Arpad wrote: > > > But what if the attacker just knows one file's name, for example index.php > > or something that's in the url in the browser. Then he/she can stole that > > file, read it, and gets other filenames because of includes/requires. > > With some work he/she can get all the files without any bruteforce > > filename guessing. > > Good point :) > > -- > Jason Wong -> Gremlins Associates -> www.gremlins.com.hk > Open Source Software Systems Integrators > * Web Design & Hosting * Internet & Intranet Applications Development * > > /* > "Facts are stupid things." > -- President Ronald Reagan > (a blooper from his speeach at the '88 GOP convention) > */ > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.general (#104396) next »