RE: [PHP] Hiding the source!

From: Date: Thu, 17 Aug 2000 17:12:33 +0000
Subject: RE: [PHP] Hiding the source!
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-12295@lists.php.net to get a copy of this message
How would somebody go about getting your php source off of your web server anyway? On Thu, 17 Aug 2000, James Atkinson wrote: > Date: Thu, 17 Aug 2000 10:15:57 -0700 > To: PHP <php-general@lists.php.net> > From: James Atkinson <james.atkinson@ebox.ca> > Subject: RE: [PHP] Hiding the source! > > The secure directory is one way to do it, but its far from the safest. > The best thing to do is move your include path to somewhere outside your > web path, well outside. That way noone without access to the system can > see the source. .htaccess passwords can be cracked so this method is a > little safer.. > > just my $0.02 > > > James Atkinson > ----------------------------------------------------------- > James Atkinson 100world > Technical Developer 512-1529 West 6th Avenue > phone: +1-604-266-4490 ext.149 Vancouver, BC, V6J 1R1 > fax: +1-604-742-1770 Canada > email: james.atkinson@100world.com http://www.100world.com > > +-------------------------------------------------------------+ > | This message may contain confidential and/or privileged | > | information. If you are not the addressee or authorized to | > | receive this for the addressee, you must not use, copy, | > | disclose or take any action based on this message or any | > | information herein. If you have received this message in | > | error, please advise the sender immediately by reply e-mail | > | and delete this message. Thank you for your cooperation. | > +-------------------------------------------------------------+ > > > > -----Original Message----- > From: Jeff Gannaway [mailto:webmaster@cactusgraphics.com] > Sent: Thursday, August 17, 2000 4:59 AM > To: ben_heuer@artlover.com; PHP > Subject: Re: [PHP] Hiding the source! > > > At 11:56 PM 8/17/00 +0800, Ben Heuer wrote: > >What do people usually say to counter these comments? What are the > >tips/tricks to hide code in PHP and CGI? Any kind of > encryption/decryption > >at runtime? (Pls forgive me if this sounds stupid! ) > > Not at all. It's a serious concern especially if part of your code > includes usernames and passwords to access MySQL Databases. > > My solution was to create a subdirectory and password protect it (the > whole > ..htaccess thing) > > Then I would make PHP files that contained truly sensitive info and save > them in that directory so they would not be accessable by web browsers > unless they had that directory's password/username. > > You can, however, include those files in publically-available PHP > scripts. > > For example, say your index.php file would access a database for info. > I > would have a chunk of the code put in a file called sql.php and save it > in > the secured directory. > > If you need more info, e-mail me. > > Good luck, > Jeff Gannaway > > > ________________________________________________________________________ > ____ > ____ > > Find the right art print for your home. > * Search by artist, color, art style and subject. > * Preview the art prints against your wall color. > > PopStreet.com is your avenue to art. > http://www.popstreet.com > ________________________________________________________________________ > ____ > ____ > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > -- Tyler Longren [Web Development] Premier Visual Services http://www.pvs2000.com

« previous php.general (#12295) next »