Re: Security on Shared Servers
| From: | Adrian Lopez | Date: | Thu, 21 Sep 2000 23:33:20 +0000 |
| Subject: | Re: Security on Shared Servers | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-3051@lists.php.net to get a copy of this message | ||
I've just been emailed a reply to my problem. The solution is to chgrp
the file containing the password to nogroup. I'd now like to share with
you all the reason for my confusion:
I had tried changing the file's group id to "root" under the mistaken
impression that the apache process ran as if owned by root. When this
resulted in the website becoming inaccessible I mistakenly assumed that
files had to be world readable. This, of course, is not the case.
Security is an important concern. I think it might be a good idea to
document this somewhere so users like myself who don't have much
experience with unix and apache are able to protect their data.
Adrian Lopez wrote:
>
> I'm working on a website that uses PostgreSQL to store user information.
> An apache server shared with other users is cheeaper than a dedicated
> one. The problem with a shared server is that people I'm sharing the
> server with can read the PHP files containing the password to my
> database. Is there any way to protect password information so I can run
> my site on a shared server? I've tried changing permissons, but then the
> site becomes inaccessible.
=============================================================
= Adrian Lopez <adrian2@caribe.net> =========================
= if (ideals != reality) return frustration; ================
=============================================================