Re: [Security-Discuss] Possible PHP hole in Perl?
Henrik Ingo <[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On Tuesday 15 June 2004 03:48, Matt Parker wrote: > Say for example your set-up was working perfectly, but then a new > exploit was found and before you had time to patch, someone got the raw > script file. The damage is twice as bad if usernames/passwords are in > there. > > I don't know what alternative there is in PHP, but in Java you can put > that stuff in a config file that is not available in the normal download > path and it is encrypted in there as well. This is possible in PHP as well. The problem is, people will just put the username and password in the script anyway. henrik -- Email: [email protected] tel: + 358-50-5259415 www: www.cafe-seed.net/~hingo pgp: www.cafe-seed.net/~hingo/PGP.txt
message.footer
(text/plain, 239 B)
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________