security and establishing DB connection
| From: | Steve Lewis | Date: | Thu, 24 Aug 2000 08:50:39 +0000 |
| Subject: | security and establishing DB connection | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-2315@lists.php.net to get a copy of this message | ||
I am building some robust tools for site administration, using PHP mod and
MySQL as principle tools with Apache and a free *nix. Currently I
require('include/database.php') in each page that requires database
interaction.
That file consists of:
<?
$db = dbname;
static $connection;
if (!isset($connection)) {
$connection = mysql_connect("localhost","dbuser","dbpword");
$setdb = mysql_select_db($db);
}
?>
Now because include/ is inside my doc_root and is world readable, it is
conceivable that it could be read by anyone on the server and is
particularly vulnerable if a hole were exploited which returned the php
code uninterpreted.
I don't want the username and password to a user account on the database
to be advertised like this (dbuser only has minimal rights anyway, but
damage could be done if data in the DB was compromised).
The only thing I can think of is to chgrp the database.php file to nobody
and chmod the file 640 as this prevents user accounts on the server from
reading the file (other than the file owner and nobody who will still be
able to read it obviously), but I am still not sleeping well at night
because it doesn't address the original problem of uninterpreted php
code.
Any suggestions?
Thanks
--Steve