RE: [PHP] Hiding the source!
| From: | Tyler Longren | Date: | Thu, 17 Aug 2000 17:12:33 +0000 |
| Subject: | RE: [PHP] Hiding the source! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12295@lists.php.net to get a copy of this message | ||
How would somebody go about getting your php source off of your web server
anyway?
On Thu, 17 Aug 2000, James Atkinson wrote:
> Date: Thu, 17 Aug 2000 10:15:57 -0700
> To: PHP <php-general@lists.php.net>
> From: James Atkinson <james.atkinson@ebox.ca>
> Subject: RE: [PHP] Hiding the source!
>
> The secure directory is one way to do it, but its far from the safest.
> The best thing to do is move your include path to somewhere outside your
> web path, well outside. That way noone without access to the system can
> see the source. .htaccess passwords can be cracked so this method is a
> little safer..
>
> just my $0.02
>
>
> James Atkinson
> -----------------------------------------------------------
> James Atkinson 100world
> Technical Developer 512-1529 West 6th Avenue
> phone: +1-604-266-4490 ext.149 Vancouver, BC, V6J 1R1
> fax: +1-604-742-1770 Canada
> email: james.atkinson@100world.com http://www.100world.com
>
> +-------------------------------------------------------------+
> | This message may contain confidential and/or privileged |
> | information. If you are not the addressee or authorized to |
> | receive this for the addressee, you must not use, copy, |
> | disclose or take any action based on this message or any |
> | information herein. If you have received this message in |
> | error, please advise the sender immediately by reply e-mail |
> | and delete this message. Thank you for your cooperation. |
> +-------------------------------------------------------------+
>
>
>
> -----Original Message-----
> From: Jeff Gannaway [mailto:webmaster@cactusgraphics.com]
> Sent: Thursday, August 17, 2000 4:59 AM
> To: ben_heuer@artlover.com; PHP
> Subject: Re: [PHP] Hiding the source!
>
>
> At 11:56 PM 8/17/00 +0800, Ben Heuer wrote:
> >What do people usually say to counter these comments? What are the
> >tips/tricks to hide code in PHP and CGI? Any kind of
> encryption/decryption
> >at runtime? (Pls forgive me if this sounds stupid! )
>
> Not at all. It's a serious concern especially if part of your code
> includes usernames and passwords to access MySQL Databases.
>
> My solution was to create a subdirectory and password protect it (the
> whole
> ..htaccess thing)
>
> Then I would make PHP files that contained truly sensitive info and save
> them in that directory so they would not be accessable by web browsers
> unless they had that directory's password/username.
>
> You can, however, include those files in publically-available PHP
> scripts.
>
> For example, say your index.php file would access a database for info.
> I
> would have a chunk of the code put in a file called sql.php and save it
> in
> the secured directory.
>
> If you need more info, e-mail me.
>
> Good luck,
> Jeff Gannaway
>
>
> ________________________________________________________________________
> ____
> ____
>
> Find the right art print for your home.
> * Search by artist, color, art style and subject.
> * Preview the art prints against your wall color.
>
> PopStreet.com is your avenue to art.
> http://www.popstreet.com
> ________________________________________________________________________
> ____
> ____
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
--
Tyler Longren
[Web Development]
Premier Visual Services
http://www.pvs2000.com