RE: [PHP] Hiding the source!

From: Date: Thu, 17 Aug 2000 17:15:57 +0000
Subject: RE: [PHP] Hiding the source!
Groups: php.general 
Request: Send a blank email to php-general+get-12294@lists.php.net to get a copy of this message
The secure directory is one way to do it, but its far from the safest. The best thing to do is move your include path to somewhere outside your web path, well outside. That way noone without access to the system can see the source. .htaccess passwords can be cracked so this method is a little safer.. just my $0.02 James Atkinson ----------------------------------------------------------- James Atkinson 100world Technical Developer 512-1529 West 6th Avenue phone: +1-604-266-4490 ext.149 Vancouver, BC, V6J 1R1 fax: +1-604-742-1770 Canada email: james.atkinson@100world.com http://www.100world.com +-------------------------------------------------------------+ | This message may contain confidential and/or privileged | | information. If you are not the addressee or authorized to | | receive this for the addressee, you must not use, copy, | | disclose or take any action based on this message or any | | information herein. If you have received this message in | | error, please advise the sender immediately by reply e-mail | | and delete this message. Thank you for your cooperation. | +-------------------------------------------------------------+ -----Original Message----- From: Jeff Gannaway [mailto:webmaster@cactusgraphics.com] Sent: Thursday, August 17, 2000 4:59 AM To: ben_heuer@artlover.com; PHP Subject: Re: [PHP] Hiding the source! At 11:56 PM 8/17/00 +0800, Ben Heuer wrote: >What do people usually say to counter these comments? What are the >tips/tricks to hide code in PHP and CGI? Any kind of encryption/decryption >at runtime? (Pls forgive me if this sounds stupid! ) Not at all. It's a serious concern especially if part of your code includes usernames and passwords to access MySQL Databases. My solution was to create a subdirectory and password protect it (the whole .htaccess thing) Then I would make PHP files that contained truly sensitive info and save them in that directory so they would not be accessable by web browsers unless they had that directory's password/username. You can, however, include those files in publically-available PHP scripts. For example, say your index.php file would access a database for info. I would have a chunk of the code put in a file called sql.php and save it in the secured directory. If you need more info, e-mail me. Good luck, Jeff Gannaway ________________________________________________________________________ ____ ____ Find the right art print for your home. * Search by artist, color, art style and subject. * Preview the art prints against your wall color. PopStreet.com is your avenue to art. http://www.popstreet.com ________________________________________________________________________ ____ ____ -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#12294) next »