Re: Encrypting a php page...



Einstein <michaelhh@xxxxxxxxx> writes:
It is a legit site, believe me you. But at the same time there is a on
and off again hack attempt from someone out there against him. He has
fairly good protection at the server level, but the PHP pages have no
encryption for the information being sent. With average traffic in the
20,000 level he is afraid of a hack using the other peoples
information.

Oh, I thought you meant storage on the server side. You do have to be
careful with that, too, you know. Anyway, use SSL a/k/a TLS.
Sci.crypt is not really the right place to ask how to do that. Talk
to your hosting provider or try a webserver-oriented newsgroup. If
you're using apache, use the built-in SSL stuff in Apache 2.x but the
docs at www.modssl.org (for Apache 1.3, back when SSL was done in a
separate module) might help you understand how to use it.

I'll reveal one little trick: the following is the cheapest place I
know to get certificates from. I think they're intended for the
reseller's hosting customers but I've bought certs a la carte from
them a few times without any problems:

http://www.theplanet.com/hosting-products/ssl/rapidssl.asp
.



Relevant Pages

  • Re: Hack attempt
    ... > I want to show everyone some logs and see if you know the hack they are ... > I supected something when apache was not running this morning. ... You have an error in your config file... ...
    (comp.os.linux.security)
  • Re: Ssh performance penalty over WANs?
    ... Not sure why you call it a "hack"; SSL VPNs have been around for a while. ... The big advantage of ssh is that it's available just about everywhere. ...
    (uk.comp.sys.mac)
  • Any Reg Hacks to force 2k/Outlook 03 to use SSL?
    ... MS says only XP sp1 with Outlook 03 will do SSL but surely there is a reg ... hack to force 2K/Outlook 03 to work as well since XP is not much more than ...
    (microsoft.public.outlook.general)
  • REMOTE_HOST different than apache error_log IP address
    ... I was looking through my apache error log and saw an erroneous entry ... one of my programs (apparently someone was trying to hack at it). ...
    (comp.infosystems.www.servers.unix)
  • Re: Lisp and Web Programming
    ... >>>recompile Apache just to write a web application in Common Lisp. ... is an excuse for the hack: those programs are deadly slow to start. ...
    (comp.lang.lisp)