Re: Keeping "Secrets" in PHP Files
| From: | B i g D o g | Date: | Fri, 28 Jun 2002 18:04:30 +0000 |
| Subject: | Re: Keeping "Secrets" in PHP Files | ||
| References: | 1 2 3 4 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-104396@lists.php.net to get a copy of this message | ||
Remember this..."if a hacker really wants in, then he/she will get in". We
just need to do our best to try and prevent it on our systems. Also
remember that most companies (people) have plans for compromised systems.
This might be something to look at...
The only 100% hack proof system is one that is not connected to the
internet. If 100% secure is what you want unplug your computer.
B i g D o g
----- Original Message -----
From: "Jason Wong" <php-general@gremlins.com.hk>
To: <php-general@lists.php.net>
Sent: Friday, June 28, 2002 11:57 AM
Subject: Re: [PHP] Keeping "Secrets" in PHP Files
> On Saturday 29 June 2002 01:20, Tamas Arpad wrote:
>
> > But what if the attacker just knows one file's name, for example
index.php
> > or something that's in the url in the browser. Then he/she can stole
that
> > file, read it, and gets other filenames because of includes/requires.
> > With some work he/she can get all the files without any bruteforce
> > filename guessing.
>
> Good point :)
>
> --
> Jason Wong -> Gremlins Associates -> www.gremlins.com.hk
> Open Source Software Systems Integrators
> * Web Design & Hosting * Internet & Intranet Applications Development *
>
> /*
> "Facts are stupid things."
> -- President Ronald Reagan
> (a blooper from his speeach at the '88 GOP convention)
> */
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php