Re: protecting your php code from other peeping toms?

From: Date: Thu, 11 Oct 2001 21:20:24 +0000
Subject: Re: protecting your php code from other peeping toms?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-70854@lists.php.net to get a copy of this message
Newsgrp@Onegeek.Com wrote: > > Now -- how else could that user get a hold of my code? Is the console locked down? > They could exploit > an insecure php script and do a simple 'move *.php *.txt' and simply > retrieve the *.txt via http. However, this would probably be unlikely and > for the most paranoid. Depends on how you've written your scripts. Do you run exec()s like exec('cp $1 $2')? Do you do any rigorous validation on incoming variables, which is a must since you really can't (and shouldn't) trust any incoming data from the user? > > So right now the problem seems to be that PHP code is hard to protect > because it is in plain text. There is a solution to that -- zend > optimizer. > I looked into that a bit. Unfortunately it does not fit into the open > source category and is quite expensive (US$2,400.00 -- or maybe I > misunderstood and it is only 24.00 =). So that seems to be out of the > option for most people. "Unfortunately it does not fit into the open source category" -- how ironic. Actually, the Optimizer is free as in beer. The Encoder costs $2400. (Although you can get the Developer Suite for $1000, which includes two IDEs, the Encoder, the Debug Server and some other stuff.) > Hopefully, all the questinos I brought up and scenerios that were > described > will pop some ideas in coder's heads. How do you guys protect code -- if > you do. What are other options that I missed. > I license my code. For work, well, it's not really up to me, and we haven't written up our licenses yet, but I'm pushing the suits for a pretty open license. Maybe something like the PHP license or QPL or something. For my own work, I'll usually GPL or BSD it. J

« previous php.general (#70854) next »