protecting your php code from other peeping toms?
| From: | newsgrp@OneGeek.com | Date: | Thu, 11 Oct 2001 00:25:24 +0000 |
| Subject: | protecting your php code from other peeping toms? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-70746@lists.php.net to get a copy of this message | ||
Hi,
First time posting. Did a quick search of the last 300 messages and
couldn't find any help. If there are any FAQs for this newsgroup, I could
take that and check those out.
My question... I want to create some great php code and install it on web
sites for my clients. Now, this code is my property and I'd like to keep it
that way. What are my options for securing this code from other eyes? I
will go into this deeper...
If I have php code sitting in someone's home directory(btw, I am using
linux), they can ftp to get it. Okay, So block FTP, telnet/ssh for that
user.
Now -- how else could that user get a hold of my code? They could exploit
an insecure php script and do a simple 'move *.php *.txt' and simply
retrieve the *.txt via http. However, this would probably be unlikely and
for the most paranoid.
What if even I had to keep FTP running? I could move the top secret PHP
scripts outside of a directory that the user didn't have FTP access to.
However, the user could run his php script from http to do a simple copy
../../*.php to *.txt.
So right now the problem seems to be that PHP code is hard to protect
because it is in plain text. There is a solution to that -- zend optimizer.
I looked into that a bit. Unfortunately it does not fit into the open
source category and is quite expensive (US$2,400.00 -- or maybe I
misunderstood and it is only 24.00 =). So that seems to be out of the
option for most people.
Let's step away from the interpreted languages and move to compiled code.
What are the options for creating compiled code and having that interact
with my PHP scripts that I don't mind others seeing. My compiled code would
be 'some great php[well not php] code' as shown in paragraph two. Compiled
code would be harder for someone to get at with ease. It is good enough for
me to work with. Of course for the most paranoid there are ways to
decompile code, but thats for the more paranoid =].
Basically, I have a bunch of classes I want to secure. PHP is plain text, a
nd that seems to be the insecure part about it. My original question was
going to be on how to get compiled code returning data to calls made from
PHP. For example: returning an array that PHP could understand from a c
program to a PHP script and then to the browser.
Hopefully, all the questinos I brought up and scenerios that were described
will pop some ideas in coder's heads. How do you guys protect code -- if
you do. What are other options that I missed.
Thank you,
Mike Hostetter