Re: Simple Security
| From: | David Robley | Date: | Mon, 11 Sep 2000 06:11:17 +0000 |
| Subject: | Re: Simple Security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-16124@lists.php.net to get a copy of this message | ||
On Mon, 11 Sep 2000, Andrew V. Romero wrote:
> I was wondering how secure is creating an html form that passes a name
> along to a php file that says something like:
> <?php
> if ($realname =="Andrew" or $realname == "andrew") {
> echo "<P><hr 6>";
> echo "<center><b>Welcome Andrew</b></center>";
> echo "The Information Entered into this Test Form Was: <br>";
> etc............
> Is something like that fairly easy to hack into, or is fairly secure? I
> am thinking the problem with that method is someone can just view that
> directory and download the php file and then view it. So is there a
> better simple way to just create a barrier to getting to certain pages?
> Thanks,
In addition to what Jason just said, I'd have to add that the circumstance
you describe would actually require some hard (stupid) work on the system
administrator's part to get to the stage where it could happen. Assuming
apache as the server, you'd need to have the directory listing facility
turned on so that a directory listing could be seen via browser, and you
would need to have php parsing of the script/directory/whatever turned off
for the casual viewer to see the source of the php script (unless you have
it there as a phps file, in which case you are asking for trouble with a
sensitive document).
There was a fairly lengthy series of discussions on various security
matters in this list recently, so you may find a skim of the archives
useful. As a first pointer, put sensitive stuff in an include file and put
the include file directory outside the web root.
--
David Robley | WEBMASTER & Mail List Admin
RESEARCH CENTRE FOR INJURY STUDIES | http://www.nisu.flinders.edu.au/
AusEinet | http://auseinet.flinders.edu.au/
Flinders University, ADELAIDE, SOUTH AUSTRALIA