Re: More - Re: PHP Security problems
| From: | Steve Werby | Date: | Thu, 08 Nov 2001 00:12:48 +0000 |
| Subject: | Re: More - Re: PHP Security problems | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-73827@lists.php.net to get a copy of this message | ||
"Chris Ross" <asip@theross.com> wrote:
> Scenario: you access a site running PHP scripts.
I assume you're talking about accessing the site via the web.
> Is it possible to
> determine the names and values of session variables running for your
> session?
No.
> Is it possible to see the PHP source code?
No. Of course, this assumes PHP files that aren't meant to be accessed
directly (include files) are outside of the web root, you don't have any
security flaws in your scripts that allow a user to change a query string
and view arbitrary world-readable files on your server and your scripts
don't have an obfuscated mechanism to display source code, return session
variables, etc.
--
Steve Werby
President, Befriend Internet Services LLC
http://www.befriend.com/