Re: More - Re: PHP Security problems

From: Date: Thu, 08 Nov 2001 00:12:48 +0000
Subject: Re: More - Re: PHP Security problems
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-73827@lists.php.net to get a copy of this message
"Chris Ross" <asip@theross.com> wrote: > Scenario: you access a site running PHP scripts. I assume you're talking about accessing the site via the web. > Is it possible to > determine the names and values of session variables running for your > session? No. > Is it possible to see the PHP source code? No. Of course, this assumes PHP files that aren't meant to be accessed directly (include files) are outside of the web root, you don't have any security flaws in your scripts that allow a user to change a query string and view arbitrary world-readable files on your server and your scripts don't have an obfuscated mechanism to display source code, return session variables, etc. -- Steve Werby President, Befriend Internet Services LLC http://www.befriend.com/

« previous php.general (#73827) next »