Re: protecting your php code from other peeping toms?
| From: | (~~~i LeoNid ~~) | Date: | Sat, 13 Oct 2001 17:21:20 +0000 |
| Subject: | Re: protecting your php code from other peeping toms? | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-70993@lists.php.net to get a copy of this message | ||
On Thu, 11 Oct 2001 11:42:28 +0200 impersonator of morten@hotpost.dk
(Morten Liebach) planted &I saw in php.general:
>On 10, Oct, 2001 at 08:25:24PM -0400, newsgrp@OneGeek.com wrote:
>
>...
>
>> If I have php code sitting in someone's home directory(btw, I am using
>> linux), they can ftp to get it. Okay, So block FTP, telnet/ssh for that
>> user.
>
>If there's any local users having a shell on the machine you basically
>can't protect your work. There are lots of localhost exploits in any
>system.
This sounds like too common a statement. Are you saying there is no way to
filter/limit access for users (not super), if there is a shell access?
Ok, lets restrict to server super (stuff) only, whithout shell access for
users. Do you entirely rely on such system?:)
In all cases it is responsibility of server _stuff_ (not its client) to
have a secure system, whithout making your life too hard.
>
>It should be a totally dedicated server.
>
This is phantasy for most. And if you have one (with all the knowledge,
needed to maintain it) will it 100% ensure you?:) Whith modern ways of
snooping, inserting Trojans .. Or just pull the plug out and don't
re-connect to InterNet ever:) That won't save you also, as internet 'll
find a way to come to you wirelessly (like F18s into God forgotten AfGany
deserts:)
...
>
>Write CGI script in a compiled language, C, C++ or INTERCAL, and run it
>from your PHP scripts.
>
Thats a possibility, if to consider it in conjunction with PHP. But better
to do it other way around, i think: run CGI compiled (small) handler stuff
first, and call your (effectively) compressed PHP from it, to take
advantage of PHP speed and functionality.
>> Hopefully, all the questinos I brought up and scenerios that were described
>> will pop some ideas in coder's heads. How do you guys protect code -- if
>> you do. What are other options that I missed.
>
>I think it's a strange thing to do, I think it's bound to end up being
>either security through obscurity or a *lot* of extra work for you, none
>of which is really smart IMHO.
>
I disagree with you. _You_ will still understand youself:) And extra work
will not be a waste of time, if you design it as a common (standardised)
tool, easily apllied to your code, beside, that you learn a lot usefull on
the way.
>A totally dedicated server where you have complete control is the only
>thing ... and secure code, *always*.
>
See my not above. "Dedication" requieres you to know all and everything by
yourself, which is impossible, or you still be relied on others:) And
better to do it openly. (That is why, btw, OPEN source code tend to be
less buggy, although I am not against technical protection of code, and
even am making a system of my own Its all the matter of judgement, where
to use what:)
>> Thank you,
>
>I hope you found this useful. :-)
>
Kinda of:)
> Morten
--
i
leo
n
id