Beefy Boxes and Bandwidth Generously Provided by pair Networks
go ahead... be a heretic

Re: How to hide a password in a script?

by archen (Pilgrim)
on Aug 06, 2004 at 13:31 UTC ( #380529=note: print w/replies, xml ) Need Help??

in reply to How to hide a password in a script?

This is a security problem and I wouldn't recommend it. But here's an idea to think about. Take a password, add a certain ammount of characters given by some algorithm in between each character (reversable obviously) then start using the pack/unpack functions. Once you have something that doesn't look anything like the password assign that value somewhere. Wherever your password is going to be transformed back, put a lot of pack/unpack statements that return values to a variable, but use the REAL pack and unpacking code to assign it to the default variable, then somewhere pick up the value in $_ . Adding a usless __DATA__ block might be a nice touch for a decoy.

I would think this would be enough to keep casual snoopers (who aren't very technical) out, but anyone who really wants to know will probably be able to tear through your script no matter what. Some of us actually have fun tearing apart sudo security schemese like this =)
  • Comment on Re: How to hide a password in a script?

Replies are listed 'Best First'.
Re^2: How to hide a password in a script?
by dataking (Acolyte) on Aug 06, 2004 at 19:44 UTC
    I was actually working on a scheme which would do something like this, but character by character, then reassemble the keyword on the fly, as opposed to storing the whole word in a single variable. But I like the _DATA_ decoy.

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://380529]
[Discipulus]: LA something a little more perlish? @mts = map {qx!mp3info -p $_!} glob '/path/*.mp3 (hazarded code)
[Discipulus]: many monks want to be hired tonight, other haired and some aired
[Lady_Aleena]: Discipulus, do glob recurse?
[Lady_Aleena]: s/do/does/;
LanX wants to be fired
[Discipulus]: i fear no
[Discipulus]: i invented also 'gired'
[Lady_Aleena]: Discipulus, then that is a problem. I wanted to find total seconds of my entire .mp3 collection to do some math on it to see how many days of continuous music i have.

How do I use this? | Other CB clients
Other Users?
Others wandering the Monastery: (10)
As of 2017-04-23 20:28 GMT
Find Nodes?
    Voting Booth?
    I'm a fool:

    Results (432 votes). Check out past polls.