Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #3030
| Path | csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!news.albasani.net!eternal-september.org!feeder.eternal-september.org!.POSTED!not-for-mail |
|---|---|
| From | "Peter H. Coffin" <hellsop@ninehells.com> |
| Newsgroups | comp.lang.php |
| Subject | Re: PHP script to only be accessed by cron |
| Date | Wed, 31 Aug 2011 07:15:41 -0500 |
| Organization | A noiseless patient Spider |
| Lines | 25 |
| Message-ID | <slrnj5s9fd.icc.hellsop@nibelheim.ninehells.com> (permalink) |
| References | <04759979-6bc8-4946-8a96-6e85775bc155@19g2000vbv.googlegroups.com> <slrnj5r0v8.icc.hellsop@nibelheim.ninehells.com> <19f7730e-74da-40fe-8f59-4ddd347bfa0f@q2g2000vbz.googlegroups.com> |
| Mime-Version | 1.0 |
| Content-Type | text/plain; charset=us-ascii |
| Content-Transfer-Encoding | 7bit |
| Injection-Info | mx04.eternal-september.org; posting-host="le/2G4+BNpieVhQI6uJ2Lw"; logging-data="14641"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+idg9iEvUClvf62cm9m08W" |
| User-Agent | slrn/0.9.9p1 (OpenBSD) |
| Cancel-Lock | sha1:wfYiRG+4pLOUGZ3D34yNN8CT3z0= |
| Xref | x330-a1.tempe.blueboxinc.net comp.lang.php:3030 |
Show key headers only | View raw
On Tue, 30 Aug 2011 19:16:00 -0700 (PDT), jwcarlton wrote:
>> > I wouldn't mind encoding the page, too, JUST in case I have a root
>> > breach (not expected, of course, but not impossible). Since I would
>> > only need to encode one page, once, would it be reasonable to use the
>> > free trial of Zend Guard? Or would you guys suggest something
>> > different?
>>
>> Way, way, way too complicated. Stop thinking "page", start thinking
>> "script file".
>
> I'm not sure that I follow. If a hacker gains root access, I don't
> want them to be able to go to the cron page and obtain the encryption
> keys in the page; otherwise, they'll be able to get all of the
> otherwise nicely secured data.
>
> If not Zend Guard, what else do you recommend?
If an attacker gets root access, inside the system, the attacker has the
encryption keys, no matter where you bury them. Might as well make sure
that nobody can get them from *outside* the system, which you can
actually do something about.
--
When C++ is your hammer, everything looks like a thumb.
-- Steven M. Haflich
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
PHP script to only be accessed by cron jwcarlton <jwcarlton@gmail.com> - 2011-08-30 17:23 -0700
Re: PHP script to only be accessed by cron "Peter H. Coffin" <hellsop@ninehells.com> - 2011-08-30 19:44 -0500
Re: PHP script to only be accessed by cron jwcarlton <jwcarlton@gmail.com> - 2011-08-30 19:16 -0700
Re: PHP script to only be accessed by cron "Peter H. Coffin" <hellsop@ninehells.com> - 2011-08-31 07:15 -0500
Re: PHP script to only be accessed by cron The Natural Philosopher <tnp@invalid.invalid> - 2011-08-31 17:48 +0100
Re: PHP script to only be accessed by cron "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-08-31 08:34 +0200
Re: PHP script to only be accessed by cron Goran <goran@nospam.com> - 2011-08-31 08:43 +0200
Re: PHP script to only be accessed by cron The Natural Philosopher <tnp@invalid.invalid> - 2011-08-31 09:20 +0100
Re: PHP script to only be accessed by cron jwcarlton <jwcarlton@gmail.com> - 2011-08-31 02:14 -0700
Re: PHP script to only be accessed by cron "Peter H. Coffin" <hellsop@ninehells.com> - 2011-08-31 07:53 -0500
Re: PHP script to only be accessed by cron The Natural Philosopher <tnp@invalid.invalid> - 2011-08-31 17:58 +0100
Re: PHP script to only be accessed by cron The Natural Philosopher <tnp@invalid.invalid> - 2011-08-31 17:45 +0100
Re: PHP script to only be accessed by cron "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-09-01 10:55 +0200
Re: PHP script to only be accessed by cron Luuk <Luuk@invalid.lan> - 2011-08-31 20:37 +0200
Re: PHP script to only be accessed by cron The Natural Philosopher <tnp@invalid.invalid> - 2011-08-31 20:49 +0100
Re: PHP script to only be accessed by cron Luuk <Luuk@invalid.lan> - 2011-09-01 19:11 +0200
Re: PHP script to only be accessed by cron The Natural Philosopher <tnp@invalid.invalid> - 2011-09-01 20:25 +0100
Re: PHP script to only be accessed by cron Luuk <Luuk@invalid.lan> - 2011-09-01 21:45 +0200
Re: PHP script to only be accessed by cron The Natural Philosopher <tnp@invalid.invalid> - 2011-09-02 00:30 +0100
Re: PHP script to only be accessed by cron Denis McMahon <denis.m.f.mcmahon@gmail.com> - 2011-09-01 10:42 +0000
csiph-web