Re: More - Re: PHP Security problems

From: Date: Thu, 08 Nov 2001 13:09:00 +0000
Subject: Re: More - Re: PHP Security problems
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-73873@lists.php.net to get a copy of this message
Is here another way to access the site? I'm I overlooking something? Chris > "Chris Ross" <asip@theross.com> wrote: >> Scenario: you access a site running PHP scripts. > > I assume you're talking about accessing the site via the web. > >> Is it possible to >> determine the names and values of session variables running for your >> session? > > No. > >> Is it possible to see the PHP source code? > > No. Of course, this assumes PHP files that aren't meant to be accessed > directly (include files) are outside of the web root, you don't have any > security flaws in your scripts that allow a user to change a query string > and view arbitrary world-readable files on your server and your scripts > don't have an obfuscated mechanism to display source code, return session > variables, etc. > > -- > Steve Werby > President, Befriend Internet Services LLC > http://www.befriend.com/ >

« previous php.general (#73873) next »