Re: Database security with PHP

From: Date: Sat, 06 Jan 2001 19:14:00 +0000
Subject: Re: Database security with PHP
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-5649@lists.php.net to get a copy of this message
> I'm using PHP on a web-server which I administrate to access & change > information in a database which is also stored on the server. This > clearly means that the username and password for editing the database > need to be accessible by PHP => need to be stored in a file which PHP > can read. We also allow users on our network to create their own > personal web-pages on this server, which is where my problem arises. > Any user can, therefore, write a PHP script which prints out the > contents of the file which contains my database username and password > (since PHP must be able to read this file) and thus gain unauthorised > access to the database. Is there any way of avoiding this? I need to > provied all of these services on one machine (i.e. obtaining a > separate machine for user web-pages is not feasible). Ideas anyone? (I > expect this is a common problem so hopefully someone can help!!!) Please use carriage returns in your emails so we can actually read them. As for your question, I would simply run two Apache instances as different user ids. Have one for the public server and another for the administrative stuff. That is the most secure solution. Another way is to turn on safe-mode. safe-mode checks the owner of the script being executed and prevents it from accessing files owned by another user id. -Rasmus

« previous php.db (#5649) next »