RE: [PHP] WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 11:45:30 +0000
Subject: RE: [PHP] WAYS OF AUTHENICATION - open discussion
Groups: php.general 
Request: Send a blank email to php-general+get-23869@lists.php.net to get a copy of this message
> I`m not talkin about people to get to know the sessions, but rather > usernames and passwords. For example: lets say that I have a > file called > connect.inc.php3 and I have included to every page that I > have. The file > itself contains the following information: > $db = mysql_connect("somehost","someuser","somepass"); > Now when somone knows the filename (inthis case > connect.inc.php3) and he > knows the variable name (in this case $db), he can include > theinc file in > his own page and echo the $db and so getting to know the mysql user > information. Well, that's a scary thought. But let's think it through (I'm brainstorming live, here, and I'm no expert, so don't take anything here for anything but speculation) The classfiles I use are in a directory on my server but not under the document root. So to include them, you would need to be running on my server. (even if they were in my document path, unless you are running on the same server the only way you could try to include them is through their URL and that does not quite work either, as code gets parsed/executed by my server before it gets sent to your to include, so you might not get what you want anyway) Unless you are running on another virtual server from the same host, and on an ISP that was a bit sloppy in configuring his system. So you *might* have access to my php include directory *if* you knew the path and put an "include ("/the/full/path") Now you *could* know the path if the ISP imposes a global structure, as it's the same as yours but on my home. But you still have to know the filenames but that's not as easy to figure out! I am not calling an include from every page but running everything through a page engine which has simple logic - most of the meat is in classes and my script creates a few objects and calls a few methods such as $myPage->generate(); so you'd be hard pressed to figure out what's going on unless you have direct read access to my php include directory. Now *if* you can figure out that I am using phplib, and you are running on the same server as I am, then I might be in trouble. Except there is no local.inc, and the real file is called from prepend_(some name here).php. And everywhere else in my script it's called from a DEFINEd name, not the real filename. So again, unless you are really *really* lucky, or you can actually directly read my files you won't be able to know which files to include. And you cannot really just call my prepend.php3 cause it only contains the filenames and your system would try to find those in *your* auto prepend directory... I guess on a sloppy ISP that might be possible, but then it's probably simpler to just try to gain access to my database directly, as it's probably not all that well configured either... Or am I wrong? Joelle Nebbe _______________________________________________________________________ Any opinions expressed in the email are those of the individual and not necessarily the company. This email and any files transmitted with it are confidential and solely for the use of the intended recipient. If you are not the intended recipient or the person responsible for delivering to the intended recipient, be advised that you have received this email in error and that any use is strictly prohibited. If you have received this email in error please notify the IT manager by telephone on 0113 243 2701 _______________________________________________________________________

« previous php.general (#23869) next »