RE: [PHP] WAYS OF AUTHENICATION - open discussion
| From: | Nebbe, Joelle | Date: | Mon, 06 Nov 2000 11:45:30 +0000 |
| Subject: | RE: [PHP] WAYS OF AUTHENICATION - open discussion | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-23869@lists.php.net to get a copy of this message | ||
> I`m not talkin about people to get to know the sessions, but rather
> usernames and passwords. For example: lets say that I have a
> file called
> connect.inc.php3 and I have included to every page that I
> have. The file
> itself contains the following information:
> $db = mysql_connect("somehost","someuser","somepass");
> Now when somone knows the filename (inthis case
> connect.inc.php3) and he
> knows the variable name (in this case $db), he can include
> theinc file in
> his own page and echo the $db and so getting to know the mysql user
> information.
Well, that's a scary thought. But let's think it through
(I'm brainstorming live, here, and I'm no expert, so don't take
anything here for anything but speculation)
The classfiles I use are in a directory on my server but not under
the document root. So to include them, you would need to be running
on my server.
(even if they were in my document path, unless you are running
on the same server the only way you could try to include them is
through their URL and that does not quite work either, as code gets
parsed/executed by my server before it gets sent to your to include,
so you might not get what you want anyway)
Unless you are running on another virtual server from the same host,
and on an ISP that was a bit sloppy in configuring his system. So you
*might*
have access to my php include directory *if* you knew the path and put an
"include ("/the/full/path")
Now you *could* know the path if the ISP imposes a global structure, as it's
the
same as yours but on my home.
But you still have to know the filenames but that's not as easy to figure
out!
I am not calling an include from every page but running everything through
a page engine which has simple logic - most of the meat is in classes
and my script creates a few objects and calls a few methods such as
$myPage->generate(); so you'd be hard pressed to figure out what's going
on unless you have direct read access to my php include directory.
Now *if* you can figure out that I am using phplib, and you are running on
the same server as I am, then I might be in trouble. Except there is no
local.inc,
and the real file is called from prepend_(some name here).php. And
everywhere
else in my script it's called from a DEFINEd name, not the real filename. So
again,
unless you are really *really* lucky, or you can actually directly read my
files
you won't be able to know which files to include. And you cannot really just
call my
prepend.php3 cause it only contains the filenames and your system would try
to
find those in *your* auto prepend directory...
I guess on a sloppy ISP that might be possible, but then it's probably
simpler to
just try to gain access to my database directly, as it's probably not all
that well
configured either...
Or am I wrong?
Joelle Nebbe
_______________________________________________________________________
Any opinions expressed in the email are those of the individual and not
necessarily the company. This email and any files transmitted with it
are confidential and solely for the use of the intended recipient.
If you are not the intended recipient or the person responsible for
delivering to the intended recipient, be advised that you have received
this email in error and that any use is strictly prohibited.
If you have received this email in error please notify the IT manager
by telephone on 0113 243 2701
_______________________________________________________________________