RE: [PHP] WAYS OF AUTHENICATION - open discussion
| From: | Siim Einfeldt aka Itpunk | Date: | Wed, 08 Nov 2000 15:25:24 +0000 |
| Subject: | RE: [PHP] WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-24325@lists.php.net to get a copy of this message | ||
Nebbe, Joelle wrote:
>Well, that's a scary thought. But let's think it through
>(I'm brainstorming live, here, and I'm no expert, so don't take
>anything here for anything but speculation)
> The classfiles I use are in a directory on my server but not under
> the document root. So to include them, you would need to be running
> on my server.
Well, yes. Keeping the confidential stuff in some publicly not accessible
folders, removes this problem (a real hacker will still find a way to get
in, but thatâ already another story).
>Now you *could* know the path if the ISP imposes a global structure, as
it's
>the same as yours but on my home.
>But you still have to know the filenames but that's not as easy to figure
> out!
>I am not calling an include from every page but running everything
through
>a page engine which has simple logic - most of the meat is in classes
>and my script creates a few objects and calls a few methods such as
>$myPage->generate(); so you'd be hard pressed to figure out what's going
>on unless you have direct read access to my php include directory.
>Now *if* you can figure out that I am using phplib, and you are running
on
>the same server as I am, then I might be in trouble. Except there is no
>local.inc,
>and the real file is called from prepend_(some name here).php. And
>everywhere else in my script it's called from a DEFINEd name, not the
real filename.
Can you tell me a bit more about this thing, privately sounds good as well
(itpunk@itpunk.com)?
>Am I wrong?
Well, it sounds pretty good to me.
Cheers
Siim Einfeldt