note 38699 added to ref.zlib

From: Date: Sat, 03 Jan 2004 16:27:31 +0000
Subject: note 38699 added to ref.zlib
Groups: php.notes 
Request: Send a blank email to php-notes+get-62858@lists.php.net to get a copy of this message
"nospam at codelock dot co dot nz" at 30-Nov-2003 10:26 wrote a silly note about "encryption" using gzip and base64. Please always remember that encryption means the usage of some kind of secret key sequence. Base64-encoding is exactly that: An encoding, that is a different representation of the same data. It does by no means hide anything from view. You can compare encoding like this: Whether I write the number "16" or "0x10", it both means sixteen. Base64-encoding works basically the same, and so does gzip-encoding. The linked "encryption" generator can be easily circumvented. You'll get a code of the form "eval(somefunctions(...))". Just change this "eval" into an "echo", and you get all your previously unencrypted code (on the "strong" setting, you have to repeat this eleven times for the resulting code, as the so-called encryption is used multiple times (encoding the encoded)). You may want to add some pretty-printing methods to get a nice view of your code. E.g. use "<pre>" HTML formatting together with htmlspecialchars(). Instead of using echo, you can as well use any other method of saving the code to a file. Those of you who absolutely have to do encryption should refer to the php module "mcrypt" (for symmetric encryption, not included by default), or think about using external PGP or GnuPG command line programs (for asymmetric encryption). ---- Manual Page -- http://www.php.net/manual/en/ref.zlib.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+38699 Delete -- http://master.php.net/manage/user-notes.php?action=delete+38699&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+38699&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#62858) next »