Re: protecting your php code from other peeping toms?
| From: | Morten Liebach | Date: | Thu, 11 Oct 2001 09:42:28 +0000 |
| Subject: | Re: protecting your php code from other peeping toms? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-70765@lists.php.net to get a copy of this message | ||
On 10, Oct, 2001 at 08:25:24PM -0400, newsgrp@OneGeek.com wrote:
...
> If I have php code sitting in someone's home directory(btw, I am using
> linux), they can ftp to get it. Okay, So block FTP, telnet/ssh for that
> user.
If there's any local users having a shell on the machine you basically
can't protect your work. There are lots of localhost exploits in any
system.
It should be a totally dedicated server.
...
> Let's step away from the interpreted languages and move to compiled code.
> What are the options for creating compiled code and having that interact
> with my PHP scripts that I don't mind others seeing. My compiled code would
> be 'some great php[well not php] code' as shown in paragraph two. Compiled
> code would be harder for someone to get at with ease. It is good enough for
> me to work with. Of course for the most paranoid there are ways to
> decompile code, but thats for the more paranoid =].
>
> Basically, I have a bunch of classes I want to secure. PHP is plain text, a
> nd that seems to be the insecure part about it. My original question was
> going to be on how to get compiled code returning data to calls made from
> PHP. For example: returning an array that PHP could understand from a c
> program to a PHP script and then to the browser.
Write CGI script in a compiled language, C, C++ or INTERCAL, and run it
from your PHP scripts.
> Hopefully, all the questinos I brought up and scenerios that were described
> will pop some ideas in coder's heads. How do you guys protect code -- if
> you do. What are other options that I missed.
I think it's a strange thing to do, I think it's bound to end up being
either security through obscurity or a *lot* of extra work for you, none
of which is really smart IMHO.
A totally dedicated server where you have complete control is the only
thing ... and secure code, *always*.
> Thank you,
I hope you found this useful. :-)
Morten
--
Morten Liebach <morten@hotpost.dk>
PGP-key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xD796A4EB
https://pc89225.stofanet.dk/ || http://pc89225.stofanet.dk/