PHP Classes

EFC/XFSS - Extended File Stealth System: Protecting uploaded files using cryptography

Recommend this page to a friend!
Stumble It! Stumble It! Bookmark in Bookmark in
  Info   Screenshots Screenshots   View files View files (8)   DownloadInstall with Composer Download .zip   Reputation   Support forum (1)   Blog    
Last Updated Ratings Unique User Downloads Download Rankings  
2010-02-23 (5 years ago) RSS 2.0 feedStarStarStarStar 70%Total: 2,182 This week: 1All time: 1,697 This week: 1,242Up
Version License PHP version Categories  
efc_xfss 1.0.1GNU Lesser Genera...4.0Files and Folders, Cryptography
Description Author  

The main idea behind "EFC/XFSS - Enhanced File Crypt/Extended File Stealth System" is to have your uploaded files safe in the server in a way that, even if someone can get them, no one can read them without knowing a few details to decrypt the files.

The class uses a random trick to select the encryption method that is used. This will always generate diferent encrypted files.

The file names are also obfuscated, so a sneaker will not know what the original format was.

This class was mainly developed to be used with GPL'ed Care2002 Medical Information System ( However, its use was postponed because most of the files uploaded were images and most of them do not have any personal identifiable info on them.

This class, in a broader sense, has yet a long way to go. For now it is simply a sub-class of part of the RC4Crypt class. It allows an easy process of encryption and decryption of uploaded files. It requires libmcrypt support and, when possible, an SSL internet connection to be used.

The class needs mcrypt PHP functions. The next challenge will be to encrypt and decrypt the files at client side, perhaps with Javascript, for those that cannot have an SSL connection, and also the creation of a replacement class for those that do not have the possibility to use libmcrypt.

The only files that you need to look at into are index.php, srcefc.php, mkconfig.php and .htaccess (the last one to use in the secured directory for strict security if you can not put it outside Web document tree).

The documentation is inside these PHP scripts.

You also need to search for the definition of __SECURE_PATH__, and modify the path in the above PHP files.

Picture of Lopo Lencastre de Almeida
Name: Lopo Lencastre de ... is available for providing paid consulting. Contact Lopo Lencastre de ... .
Classes: 3 packages by
Country: Portugal Portugal
Age: 48
All time rank: 102714 in Portugal Portugal
Week rank: 664 Up12 in Portugal Portugal Up

  • Screenshot
  Files folder image Files  
File Role Description
Accessible without login Plain text file README.txt Doc. Some documentation for those that don't want to read the code inside the files.
Accessible without login Plain text file .htaccess Data Simple protection for SECURED directory under Apache
Accessible without login Plain text file cleanex.php Aux. Small utility to clean up your test SECURED directory. Don't use it in a production environment without caution.
Plain text file crypt_class.php Class Slightly modified RC4Crypt Class
Plain text file efc.class.php Class The Class
Accessible without login Plain text file index.php Example Test file. Read it to see how to use the Class.
Accessible without login Plain text file mkconfig.php Example Generates config for test program.
Accessible without login Plain text file srcefc.php Example Test file used by index.php. Read it to see how to use the Class to retrieve encrypted files.

 Version Control Unique User Downloads Download Rankings  
 0%Total:2,182All time:1,697
 This week:1This week:1,242Up
 User Ratings  
 All time