Re: Proposal: Establish DB connections during module_init
| From: | Manuel Lemos | Date: | Thu, 08 Jun 2000 02:38:35 +0000 |
| Subject: | Re: Proposal: Establish DB connections during module_init | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-20531@lists.php.net to get a copy of this message | ||
Precedence: bulk
Hello jah,
On 07-Jun-00 20:25:33, you wrote:
>On 7 Jun 2000, Manuel Lemos wrote:
>> ><VirtualHost www.php.net>
>> > php_admin_value mysql.default_host=localhost
>> > php_admin_value mysql.default_user=rasmus
>> > php_admin_value mysql.default_password=foobar
>> > php_admin_value mysql.autoconnect=On
>> > ...
>> ></VirtualHost>
>>
>> OTOH, I don't know if developers will want to have their database passwords
>> in clear text scattered for more places that it should. Some people use
>> databases to protect the content of their sites. Having passwords in the
>> Apache configuration makes it easier for that protection be defeated. It
>> would be better (not absolutely safe though) to have database password
>> defined in PHP code where the user thinks its best.
>I'd say httpd.conf is a lot of safer place to put cleartext passwords than
>anywhere in PHP code. Apache usually starts as root privileges, reads
>httpd.conf, starts forking children, and only the children change their
>uid/gid to something unprivileged. So, httpd.conf can have the privileges
>0700 and be owned by root, unlike PHP code... In fact, even the users
>themselves don't need to know their username and password to access the
>database, because it can be assigned by sysadm per virtualhost/directory.
I guess I am not explaining my point clear. Given that there is no 100%
secure system, security level may be defined as the amount of time that
an hacker takes to cause harm to the system. Once inside of a system, an
hacker looks for informations in predictable places.
Once an hacker knows that site is served by PHP, he'll look for database
passwords first in the most obvious places. If this feature is deployed as
proposed, httpd.conf becomes the most obvious place to start the search. If
the password is there, the search is over and the site is hacked faster,
so the security level is effectively lower.
Of course the developer may not provide a password in httpd.conf, but that
way he may not benefit of the startup speed increase.
I believe that Zeev's suggestion of letting the process startup code be
defined in PHP somewhere else is a little better, but not much more though.
Don't get me wrong, I don't think this sufficient motive to not implement
this feature. It may only make a difference of a few minutes or even
seconds for a site to be hacked by storing passwords elsewhere less
predictable. Banks still think that's worthy because the robbers may be
retarded long enough for the police to arrive in time.
Regards,
Manuel Lemos
Web Programming Components using PHP Classes.
Look at: http://phpclasses.UpperDesign.com/?user=mlemos@acm.org
--
E-mail: mlemos@acm.org
URL: http://www.mlemos.e-na.net/
PGP key: http://www.mlemos.e-na.net/ManuelLemos.pgp
--