navigation
a webmaster learning community
     Home    Register     Search      Help      Login    
Sponsors

Shopping Cart Software
Ecommerce software integrated into Frontpage, Dreamweaver and Golive templates. No monthly fees and available in ASP and PHP versions.

Website Templates
We also have a wide selection of Dreamweaver, Expression Web and Frontpage templates as well as webmaster tools and CSS layouts.

Frontpage website templates
Creative Website Templates for FrontPage, Dreamweaver, Flash, SwishMax

Search Forums
 

Advanced search
Recent Posts

 Todays Posts
 Most Active posts
 Posts since last visit
 My Recent Posts
 Mark posts read

Microsoft MVP

 

Zend and IonCube compromised

 
View related threads: (in this forum | in all forums)

Logged in as: Guest
Users viewing this topic: none
Printable Version 

All Forums >> Community >> Computer Software and Hardware issues >> Zend and IonCube compromised
Page: [1]
 
BobbyDouglas

 

Posts: 5452
Joined: 5/15/2003
From: Arizona
Status: offline

 
Zend and IonCube compromised - 1/12/2008 16:37:34   
I am sure that many developers have worked with scripts/programs before that are "encoded" using the popular Zend or IonCube encoders.

Unfortunately, beginning last year, there have been many cases where these encoded files have been decoded. Zend is much easier to decode than IonCube, but both are 100% possible.

Comments and extra space are not included in the decoded version, so you don't have the exact file that was encoded, but you have the code for it.

IonCube claims to have "obfuscated bytecode execution engine" which would basically make it impossible to decode the file. The idea behind that, is you take machine level language, and try to convert it back to a high level language (such as C++), before it was compiled to machine level.


What does this mean for everyone?


For lazy developers, who relied on their hidden code to be the main security measures, will be prone to SQL injections, hacks, and other things that will be able to compromise the software. Basically, anyone who decided to code lazy because they knew their code couldn't be seen, will have to go through every piece of code to make sure there are not any open holes.

Developers who coded with security in mind from the beginning should be ok.

< Message edited by BobbyDouglas -- 1/12/2008 16:44:59 >


_____________________________

Arizona Web Design - Mr Bobs Web Design in Arizona
The Arizona Web Hosting Challenge
BobbyDouglas

 

Posts: 5452
Joined: 5/15/2003
From: Arizona
Status: offline

 
RE: Zend and IonCube compromised - 1/15/2008 15:32:31   
Ok nobody cares :)

_____________________________

Arizona Web Design - Mr Bobs Web Design in Arizona
The Arizona Web Hosting Challenge

(in reply to BobbyDouglas)
Ryokotsusai

 

Posts: 248
Joined: 10/5/2005
Status: offline

 
RE: Zend and IonCube compromised - 1/16/2008 2:10:39   
PHP or other languages like it don't seem to come up here all that often...

_____________________________

The world is more like it is now than it ever has been before.
--Dwight Eisenhower

(in reply to BobbyDouglas)
Page:   [1]

All Forums >> Community >> Computer Software and Hardware issues >> Zend and IonCube compromised
Page: [1]
Jump to: 1





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts