Re: Simple Security

From: Date: Mon, 11 Sep 2000 06:11:17 +0000
Subject: Re: Simple Security
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-16124@lists.php.net to get a copy of this message
On Mon, 11 Sep 2000, Andrew V. Romero wrote: > I was wondering how secure is creating an html form that passes a name > along to a php file that says something like: > <?php > if ($realname =="Andrew" or $realname == "andrew") { > echo "<P><hr 6>"; > echo "<center><b>Welcome Andrew</b></center>"; > echo "The Information Entered into this Test Form Was: <br>"; > etc............ > Is something like that fairly easy to hack into, or is fairly secure? I > am thinking the problem with that method is someone can just view that > directory and download the php file and then view it. So is there a > better simple way to just create a barrier to getting to certain pages? > Thanks, In addition to what Jason just said, I'd have to add that the circumstance you describe would actually require some hard (stupid) work on the system administrator's part to get to the stage where it could happen. Assuming apache as the server, you'd need to have the directory listing facility turned on so that a directory listing could be seen via browser, and you would need to have php parsing of the script/directory/whatever turned off for the casual viewer to see the source of the php script (unless you have it there as a phps file, in which case you are asking for trouble with a sensitive document). There was a fairly lengthy series of discussions on various security matters in this list recently, so you may find a skim of the archives useful. As a first pointer, put sensitive stuff in an include file and put the include file directory outside the web root. -- David Robley | WEBMASTER & Mail List Admin RESEARCH CENTRE FOR INJURY STUDIES | http://www.nisu.flinders.edu.au/ AusEinet | http://auseinet.flinders.edu.au/ Flinders University, ADELAIDE, SOUTH AUSTRALIA

« previous php.general (#16124) next »