Current location: Hot Scripts Forums » Programming Languages » PHP » Posting Source Code Makes Website Vulnerable?


Posting Source Code Makes Website Vulnerable?

Reply
  #1 (permalink)  
Old 06-27-06, 06:04 PM
AthrinaV AthrinaV is offline
New Member
 
Join Date: Jun 2006
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Posting Source Code Makes Website Vulnerable?

I am developing a new site and I want to put up all of my source codes on a "SourceCode.php" page that will be linked from index.php. I used a lot of open source programs to help me with the site so I want to share by making my codes public. If I do put up a source code page, I don't want to password protect it.

But I am worried that making the source codes public will compromise security on my website. Of course I won't display passwords or database information but anything else like the variable names will be available. The page is coded using PHP and requires login and registration to enter the site. I am mainly worried that people will be able to type in URL strings that will give them access to other people's accounts.

The site uses query strings such as index.php?action=profile&id=mpz5 but does not pass password information via URL strings.

If you need to see my site to answer, I would be happy to be give the site's name but since it's not finished yet, I don't want to display it.

Any answer would be helpful. Thanks a lot.
Reply With Quote
  #2 (permalink)  
Old 06-27-06, 07:51 PM
Acecool's Avatar
Acecool Acecool is offline
Aspiring Coder
 
Join Date: Nov 2003
Posts: 506
Thanks: 0
Thanked 0 Times in 0 Posts
This can be a touchy question, however a well coded website might not have the security issues so posting code does no harm...

However, if you do post the source code, some people may find errors in the code and exploit them, others will inform you right away...

I would say only allow REGISTERED users to view source code, that way you can track who has seen it.. Then if anyone does use any exploits available, you can track the ip and match it up so you know who did it.
__________________
Check Acecoolco.com for PHP Tutorials, and other tuts
If you plan on contacting me, please read this: Legal Terms & Conditions
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Hiding/protecting source code and searching the forum! TwoD JavaScript 12 10-28-11 04:22 AM
News:E-XD++ MFC Library Professional Edition V9.20 is released (100% Source Code)! jackonlyone General Advertisements 0 02-21-06 09:58 PM
problem with php code for website djengineer PHP 3 02-13-06 07:25 PM
FS: Prozilla Memberships (Turnkey Sites) - $10-15 less than Retail! rockergrrl General Advertisements 0 08-11-04 12:05 AM
Look for a source code bionicsamir Script Requests 3 01-29-04 05:21 PM


All times are GMT -5. The time now is 07:18 AM.
vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.