Re: More - Re: PHP Security problems
| From: | Chris Ross | Date: | Thu, 08 Nov 2001 13:09:00 +0000 |
| Subject: | Re: More - Re: PHP Security problems | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-73873@lists.php.net to get a copy of this message | ||
Is here another way to access the site? I'm I overlooking something?
Chris
> "Chris Ross" <asip@theross.com> wrote:
>> Scenario: you access a site running PHP scripts.
>
> I assume you're talking about accessing the site via the web.
>
>> Is it possible to
>> determine the names and values of session variables running for your
>> session?
>
> No.
>
>> Is it possible to see the PHP source code?
>
> No. Of course, this assumes PHP files that aren't meant to be accessed
> directly (include files) are outside of the web root, you don't have any
> security flaws in your scripts that allow a user to change a query string
> and view arbitrary world-readable files on your server and your scripts
> don't have an obfuscated mechanism to display source code, return session
> variables, etc.
>
> --
> Steve Werby
> President, Befriend Internet Services LLC
> http://www.befriend.com/
>