Re: Security on Shared Servers
| From: | john slee | Date: | Fri, 22 Sep 2000 05:18:50 +0000 |
| Subject: | Re: Security on Shared Servers | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-3053@lists.php.net to get a copy of this message | ||
On Thu, Sep 21, 2000 at 10:02:24PM +0000, Adrian Lopez wrote:
> I'm working on a website that uses PostgreSQL to store user
> information. An apache server shared with other users is cheeaper
> than a dedicated one. The problem with a shared server is that people
> I'm sharing the server with can read the PHP files containing the
> password to my database. Is there any way to protect password
> information so I can run my site on a shared server? I've tried
> changing permissons, but then the site becomes inaccessible.
apache 2.0 has a good solution for this problem. unfortunately its not
stable yet. it essentially lets you run different <virtualhost>s as
different uid/gid. hence, you can have decent strict permissions on
each site, and have them not be able to interfere with each other.
search for 'PerChild' on apachetoday.com.
in between now and apache2 release, you might consider patching php to
add an option to force the database username in pg_connect, and ignore
any user's setting for that. that combined with safe_mode_exec or
whatever it is, should stop people prying into others' databases.
i did have a patch to do just that (not my workmanship), and now i can't
find it. oh well.
of course if you're not the server admin this is all rather useless :)
j.
--
.----------+---------------------------------.
|John Slee `-------. <indigoid@chirp.com.au>|
|Chirp Web Design | http://www.chirp.com.au|
|Phone 02 62301871 `--------. 02 62301515 Fax|
`---------------------------+----------------'