Re: "blackboxing" my global functions
| From: | Mike E | Date: | Mon, 23 Oct 2000 19:51:01 +0000 |
| Subject: | Re: "blackboxing" my global functions | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-21854@lists.php.net to get a copy of this message | ||
But they will need to know the filename, which you can hide.
yeah yeah I know; security through obscurity isn't security...
Mike
On Sun, Oct 22, 2000 at 11:18:31PM -0400, Michael Stearne wrote:
> Ah, hacker. :-)
>
>
>
> Lawrence.Sheed@dfait-maeci.gc.ca wrote:
>
> > It won't work though.
> >
> > If the files are accessible by Apache (and php by because apache runs it)
> > then they can just do a file open, read into a string and print.
> >
> > eg:
> >
> > $filename = "your_secret_file_here.php";
> >
> > $fd = fopen( $filename, "r" );
> > $contents = fread( $fd, filesize( $filename ) );
> > fclose( $fd );
> > print ($contents);
> >
> > -----Original Message-----
> > From: Michael Stearne [mailto:mstearne@entermix.com]
> > Sent: October 23, 2000 11:13 AM
> > To: David Robley
> > Cc: Theodore Jones; PHP General List
> > Subject: Re: [PHP] "blackboxing" my global functions
> >
> > That is a good idea.
> >
> > David Robley wrote:
> >
> > > On Mon, 23 Oct 2000, Theodore Jones wrote:
> > > > Hello,
> > > >
> > > > I act as my own full-service hosting and design company and I use PHP in
> > > > some of my site designs.
> > > >
> > > > I have spent considerable time on some of my functions and such which I
> > > > generally like to put into an include file which can be accessed by all
> > > > pages "globally" within the site. What I am wondering is, how can I
> > > > "black-box" this global function include file such that it is
> > > > protected
> > > > from the site "owners" FTP'ing in and downloading/viewing, but is
> > > > still
> > > > accessible through the HTTP interactions to pump out HTML to the
> > > > browser?
> > > >
> > > > In a sense I consider the PHP programming I have done my "investment"
> > > > and "property" and not a part of the design of the site sold to the
> > > > client, so I seek to protect my investment and keep them from just
> > > > running off with my code and hosting on a different server.
> > > >
> > > > If anyone has any ideas (perhaps I'm missing something obvious as a
> > > > solution), please advise.
> > > >
> > > > Thanks in Advance,
> > > >
> > > > ~ Theo
> > >
> > > Put your include files in a directory that is not under the web root, and
> > > that can't be accessed via ftp except by the good guys.
> > >
> > > --
> > > David Robley | WEBMASTER & Mail List Admin
> > > RESEARCH CENTRE FOR INJURY STUDIES |
> > > http://www.nisu.flinders.edu.au/
> > > AusEinet |
> > > http://auseinet.flinders.edu.au/
> > > Flinders University, ADELAIDE, SOUTH AUSTRALIA
> > >
> > > --
> > > PHP General Mailing List (http://www.php.net/)
> > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > > For additional commands, e-mail: php-general-help@lists.php.net
> > > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-general-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-general-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
--
Mike Erickson <mee@quidquam> http://www.quidquam.com/
"Hatred is the coward's revenge for being intimidated" - George Bernard Shaw