Re: Security on Shared Servers

From: Date: Fri, 22 Sep 2000 05:18:50 +0000
Subject: Re: Security on Shared Servers
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-3053@lists.php.net to get a copy of this message
On Thu, Sep 21, 2000 at 10:02:24PM +0000, Adrian Lopez wrote: > I'm working on a website that uses PostgreSQL to store user > information. An apache server shared with other users is cheeaper > than a dedicated one. The problem with a shared server is that people > I'm sharing the server with can read the PHP files containing the > password to my database. Is there any way to protect password > information so I can run my site on a shared server? I've tried > changing permissons, but then the site becomes inaccessible. apache 2.0 has a good solution for this problem. unfortunately its not stable yet. it essentially lets you run different <virtualhost>s as different uid/gid. hence, you can have decent strict permissions on each site, and have them not be able to interfere with each other. search for 'PerChild' on apachetoday.com. in between now and apache2 release, you might consider patching php to add an option to force the database username in pg_connect, and ignore any user's setting for that. that combined with safe_mode_exec or whatever it is, should stop people prying into others' databases. i did have a patch to do just that (not my workmanship), and now i can't find it. oh well. of course if you're not the server admin this is all rather useless :) j. -- .----------+---------------------------------. |John Slee `-------. <indigoid@chirp.com.au>| |Chirp Web Design | http://www.chirp.com.au| |Phone 02 62301871 `--------. 02 62301515 Fax| `---------------------------+----------------'

« previous php.db (#3053) next »