House of Hackers

k3vin mitnick

lets speak about php Encryption to protection config.php

lets speak about php Encryption to protection config.php ???

Share

Reply to This

Replies to This Discussion

The big problem, is the key will be store some where as available as the config.php... So it doesn't do much.

Reply to This

coool but what do you think about the last Zend_Guard ???

Reply to This

So encryption like Zend_guard.

config.php can't be encrypted directly using zend_guard. By encrypted it by mcrypt fonctions, it can be done, if there is a key in a crypted file. But, the php bitcode, is available to third party after it's decrypt and send to the php execution engine. So, if you have access to the file, just modify the php.ini and use a bitcode decoder.

Yes, it's more secure, will create some difficulty for the majority of pirates. But any good hackers, it's not a big problem. Using a server licence, the attacker will need to run the decoder on the server, and not offline.

Reply to This

So did I answer with a good response?

Reply to This

cooool ;-)) we need to protect all the system

Reply to This

I'm doing PHP security audit, if you ever need it.

Reply to This

thankss man its cooool

Reply to This

RSS

About

pdp pdp created this Ning Network.

© 2009   Created by pdp on Ning.   Create a Ning Network!

Badges  |  Report an Issue  |  Privacy  |  Terms of Service

Sign in to chat!