RE: [PHP] Hiding the source!
| From: | James Atkinson | Date: | Thu, 17 Aug 2000 17:15:57 +0000 |
| Subject: | RE: [PHP] Hiding the source! | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-12294@lists.php.net to get a copy of this message | ||
The secure directory is one way to do it, but its far from the safest.
The best thing to do is move your include path to somewhere outside your
web path, well outside. That way noone without access to the system can
see the source. .htaccess passwords can be cracked so this method is a
little safer..
just my $0.02
James Atkinson
-----------------------------------------------------------
James Atkinson 100world
Technical Developer 512-1529 West 6th Avenue
phone: +1-604-266-4490 ext.149 Vancouver, BC, V6J 1R1
fax: +1-604-742-1770 Canada
email: james.atkinson@100world.com http://www.100world.com
+-------------------------------------------------------------+
| This message may contain confidential and/or privileged |
| information. If you are not the addressee or authorized to |
| receive this for the addressee, you must not use, copy, |
| disclose or take any action based on this message or any |
| information herein. If you have received this message in |
| error, please advise the sender immediately by reply e-mail |
| and delete this message. Thank you for your cooperation. |
+-------------------------------------------------------------+
-----Original Message-----
From: Jeff Gannaway [mailto:webmaster@cactusgraphics.com]
Sent: Thursday, August 17, 2000 4:59 AM
To: ben_heuer@artlover.com; PHP
Subject: Re: [PHP] Hiding the source!
At 11:56 PM 8/17/00 +0800, Ben Heuer wrote:
>What do people usually say to counter these comments? What are the
>tips/tricks to hide code in PHP and CGI? Any kind of
encryption/decryption
>at runtime? (Pls forgive me if this sounds stupid! )
Not at all. It's a serious concern especially if part of your code
includes usernames and passwords to access MySQL Databases.
My solution was to create a subdirectory and password protect it (the
whole
.htaccess thing)
Then I would make PHP files that contained truly sensitive info and save
them in that directory so they would not be accessable by web browsers
unless they had that directory's password/username.
You can, however, include those files in publically-available PHP
scripts.
For example, say your index.php file would access a database for info.
I
would have a chunk of the code put in a file called sql.php and save it
in
the secured directory.
If you need more info, e-mail me.
Good luck,
Jeff Gannaway
________________________________________________________________________
____
____
Find the right art print for your home.
* Search by artist, color, art style and subject.
* Preview the art prints against your wall color.
PopStreet.com is your avenue to art.
http://www.popstreet.com
________________________________________________________________________
____
____
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net