Re: Security on Shared Servers

From: Date: Thu, 21 Sep 2000 23:33:20 +0000
Subject: Re: Security on Shared Servers
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-3051@lists.php.net to get a copy of this message
I've just been emailed a reply to my problem. The solution is to chgrp the file containing the password to nogroup. I'd now like to share with you all the reason for my confusion: I had tried changing the file's group id to "root" under the mistaken impression that the apache process ran as if owned by root. When this resulted in the website becoming inaccessible I mistakenly assumed that files had to be world readable. This, of course, is not the case. Security is an important concern. I think it might be a good idea to document this somewhere so users like myself who don't have much experience with unix and apache are able to protect their data. Adrian Lopez wrote: > > I'm working on a website that uses PostgreSQL to store user information. > An apache server shared with other users is cheeaper than a dedicated > one. The problem with a shared server is that people I'm sharing the > server with can read the PHP files containing the password to my > database. Is there any way to protect password information so I can run > my site on a shared server? I've tried changing permissons, but then the > site becomes inaccessible. ============================================================= = Adrian Lopez <adrian2@caribe.net> ========================= = if (ideals != reality) return frustration; ================ =============================================================

« previous php.db (#3051) next »