You are here: Re: Cracking encrypted data? « PHP Programming Language « IT news, forums, messages
Re: Cracking encrypted data?

Posted by Chung Leong on 12/18/77 11:50

veg_all@yahoo.com wrote:
> Chung Leong wrote:
> > If someone breaks into your server they'll be able to find the key.
> > Obviously it has to be sitting somewhere.
>
> Actually I manually encrypt everything when a client first starts.
> After
> that they just use a cookie to send the key. So I dont store it
> anywhere
> on the server.

Hmmm...That might kind of work for protecting transcient data. Then
again, I presume that you're generating the key using one of the random
functions in PHP. Knowing the time when the key is generated (from the
server log) and the process id, an attacker would be able to narrow the
range of possible keys considerably. We're assuming here the server is
properly set up and the attacker only has access to the web server
account.

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация