note 38699 added to ref.zlib
| From: | svenr at selfhtml dot org | Date: | Sat, 03 Jan 2004 16:27:31 +0000 |
| Subject: | note 38699 added to ref.zlib | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-62858@lists.php.net to get a copy of this message | ||
"nospam at codelock dot co dot nz" at 30-Nov-2003 10:26 wrote a silly note about
"encryption" using gzip and base64.
Please always remember that encryption means the usage of some kind of secret key sequence.
Base64-encoding is exactly that: An encoding, that is a different representation of the same data.
It does by no means hide anything from view.
You can compare encoding like this: Whether I write the number "16" or "0x10",
it both means sixteen. Base64-encoding works basically the same, and so does gzip-encoding.
The linked "encryption" generator can be easily circumvented. You'll get a code of
the form "eval(somefunctions(...))".
Just change this "eval" into an "echo", and you get all your previously
unencrypted code (on the "strong" setting, you have to repeat this eleven times for the
resulting code, as the so-called encryption is used multiple times (encoding the encoded)). You may
want to add some pretty-printing methods to get a nice view of your code. E.g. use
"<pre>" HTML formatting together with htmlspecialchars().
Instead of using echo, you can as well use any other method of saving the code to a file.
Those of you who absolutely have to do encryption should refer to the php module "mcrypt"
(for symmetric encryption, not included by default), or think about using external PGP or GnuPG
command line programs (for asymmetric encryption).
----
Manual Page -- http://www.php.net/manual/en/ref.zlib.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+38699
Delete -- http://master.php.net/manage/user-notes.php?action=delete+38699&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+38699&report=yes
Search -- http://master.php.net/manage/user-notes.php