Re: Follow up - PHP Security problems

From: Date: Wed, 07 Nov 2001 20:09:35 +0000
Subject: Re: Follow up - PHP Security problems
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-73788@lists.php.net to get a copy of this message
We are using PHP's graphic library, but instead of creating images using PHP (which we can do but they suck), we're using the library to reference existing images. The 102342143 part conveys meaning ONLY to our encryption/decryption logarithm. If that number decrypts to the letter "a", then the image "a.gif" will be returned to the page while NEVER revealing the true file name. Further, the letter "a" could encrypt to an infinite number of values we would use to reference the file. >> Instead of referencing the actual filename of the image in the source file >> (from here known as "SrcFile"), reference a file (from here known as >> "ImgFile") that will grab the image. Use an encryption method in the >> SrcFile to create a value that corresponds to the image you want to display, >> and pass that value to the ImgFile. The ImgFile will decrypt the code, grab >> the appropriate image, and return the image to the SrcFile. So, instead of >> seeing <img src="one.gif"><img src="two.gif"> in the >> SrcFile, all you see is >> <img src="ImgFile.php3?img=102342143"><img >> src="ImgFile.php3?img=342014253"> >> - and those "img=" values are constantly changing! >> >> There is more tech speak, but I'll spare you. > > =thanks for thinking of me > > =but.... > if our less-than-friendly miscreant changed his email-reading program it would > see the tag <img > src="ImgFile.php3?img=102342143"> and not bother with the image itself IF the > 102342143 part conveys meaning (in > relation to your site registration). > > =When Daniel responded/explained, it seemed that a really good idea would be > to use PHP's graphics library > (sorry have no expertise with that) to generate the graphical form of the > 'numbers' (or could it be used to join > a series of number graphics together into one file?) and then the img > src=filename could be identical in all > cases (and thus to a program), but the dynamically generated content would be > different and could only > interpreted by the (human) eye... > > =Guess it's not easy to give away all those prizes for free, huh! > =dn > > >>> In the meantime we are >>>> going to create something simular to altavista and yahoo verification >>>> check. >>>> Basically an image with different letters and they have to put the correct >>>> letters in. They only have to do this once and then the account is >>>> activated >>>> and can submit tickets. >>>> >>>> If any one know where I can get info on creating this process or one >>>> simular >>>> with PHP that would be great. >>> >>> >>> =I have to ask: if such miscreants can set up an automated system which will >>> even respond to email (text) >>> registration numbers/web pages, how will sending the same as graphics help? >>> >>> =Surely if they can write a program to work off "123" they can also work off >>> <img src="one.gif"> <img >>> src="two.gif"> <img src="three.gif">? >>> >>> =dn >>> >> >> >> -- >> PHP General Mailing List (http://www.php.net/) >> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net >> For additional commands, e-mail: php-general-help@lists.php.net >> To contact the list administrators, e-mail: php-list-admin@lists.php.net >> >> >

« previous php.general (#73788) next »