Re: Re: Zend encoding and security

From: Date: Fri, 09 May 2003 13:22:03 +0000
Subject: Re: Re: Zend encoding and security
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-147004@lists.php.net to get a copy of this message
Please note that the Turck developer is discouraging commericial use of the encoder until Turck 1.4 because the file format may change at that point. I've been using the Turck MM Cache for 3 months now and the performance is amazing :) Jason Manuel Lemos wrote:
Hello, On 05/08/2003 03:46 PM, Larry Vanyard wrote:
I've been looking into the Zend encoder, for it's security benefits. However, it seems to me that it's really designed more to be a performance booster, rather than a security tool (ie: the security side is just more of a nice side-effect). I've searched through google/newsgroups/etc and haven't really seen any attacks against it's encoding methods. Does anyone have any thoughts about Zend encoding as a security mechanism? Is it really currently "ubreakable"?
I depends on what you call unbreakable. Sure it is possible to hack the Zend engine and intercept the Zend opcodes decoded by the Zend optimizer before they run. The question is what would you do with a bunch of optimized opcodes. You will most likely find any passwords in the compiled opcodes but you will hardly reverse engineer to anything similar to your original source code. It is almost as good as C code compiled into assembly code. This means that if you want to hack some encoded PHP scripts, you can but it will not be easy. The point of protections is not to make it impossible to break but rather to make it difficult. On a side note, it seems that Turck has just released an encoding extension that pratically matches Zend performance as it also includes an optimizer. Since it was already a cache extension it seems to provide as an Open Source all the products that Zend has been charging thousands of dollars! http://www.turcksoft.com/en/e_mmc.htm


« previous php.general (#147004) next »