How do you make MySQL users so they can only view there database and not others while using php4
| From: | Dave Torres | Date: | Fri, 11 May 2001 21:06:24 +0000 |
| Subject: | How do you make MySQL users so they can only view there database and not others while using php4 | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-9261@lists.php.net to get a copy of this message | ||
I have some what of a security issue that I can't seem to solve.
I run php4 and MySQL on a FreeBSD server with Apache 1.3 as the webserver
and have users that I allow access to there personal database. (example:
user johndoe uses database johndoe).
I can configure "johndoe" so he can only have access to his database and
tables with in his database however they can still use MySQL functions like
mysql_list_db to see all databases. They can't alter or read them, but it
seem to me being able to display
all database names could cause a problem.
Has anyone had this same problem, and if so is there a way to stop any php
user with a mysql account to view all database?
Help Please, Thanks!
dave@afnetinc.com