Re: protecting your php code from other peeping toms?
| From: | J Smith | Date: | Thu, 11 Oct 2001 21:20:24 +0000 |
| Subject: | Re: protecting your php code from other peeping toms? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-70854@lists.php.net to get a copy of this message | ||
Newsgrp@Onegeek.Com wrote:
>
> Now -- how else could that user get a hold of my code?
Is the console locked down?
> They could exploit
> an insecure php script and do a simple 'move *.php *.txt' and simply
> retrieve the *.txt via http. However, this would probably be unlikely and
> for the most paranoid.
Depends on how you've written your scripts. Do you run exec()s like
exec('cp $1 $2')? Do you do any rigorous validation on incoming variables,
which is a must since you really can't (and shouldn't) trust any incoming
data from the user?
>
> So right now the problem seems to be that PHP code is hard to protect
> because it is in plain text. There is a solution to that -- zend
> optimizer.
> I looked into that a bit. Unfortunately it does not fit into the open
> source category and is quite expensive (US$2,400.00 -- or maybe I
> misunderstood and it is only 24.00 =). So that seems to be out of the
> option for most people.
"Unfortunately it does not fit into the open source category" -- how ironic.
Actually, the Optimizer is free as in beer. The Encoder costs $2400.
(Although you can get the Developer Suite for $1000, which includes two
IDEs, the Encoder, the Debug Server and some other stuff.)
> Hopefully, all the questinos I brought up and scenerios that were
> described
> will pop some ideas in coder's heads. How do you guys protect code -- if
> you do. What are other options that I missed.
>
I license my code. For work, well, it's not really up to me, and we haven't
written up our licenses yet, but I'm pushing the suits for a pretty open
license. Maybe something like the PHP license or QPL or something. For my
own work, I'll usually GPL or BSD it.
J