Re: Proposal: Establish DB connections during module_init
| From: | Teodor Cimpoesu | Date: | Thu, 08 Jun 2000 13:02:13 +0000 |
| Subject: | Re: Proposal: Establish DB connections during module_init | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-20568@lists.php.net to get a copy of this message | ||
Hi Manuel!
On Thu, 08 Jun 2000, Manuel Lemos wrote:
> >I'd say httpd.conf is a lot of safer place to put cleartext passwords than
> >anywhere in PHP code. Apache usually starts as root privileges, reads
> >httpd.conf, starts forking children, and only the children change their
> >uid/gid to something unprivileged. So, httpd.conf can have the privileges
>
> I guess I am not explaining my point clear. Given that there is no 100%
> secure system, security level may be defined as the amount of time that
> an hacker takes to cause harm to the system. Once inside of a system, an
> hacker looks for informations in predictable places.
>
> Once an hacker knows that site is served by PHP, he'll look for database
> passwords first in the most obvious places. If this feature is deployed as
> proposed, httpd.conf becomes the most obvious place to start the search. If
> the password is there, the search is over and the site is hacked faster,
> so the security level is effectively lower.
But, if I set my httpd.conf to 0.0/600 and you manage
to read it, it means you already have root access, so what else do
you need the DB passwords for?
>
> Of course the developer may not provide a password in httpd.conf, but that
> way he may not benefit of the startup speed increase.
>
> I believe that Zeev's suggestion of letting the process startup code be
> defined in PHP somewhere else is a little better, but not much more though.
sure, the "secret file" must be declared somewhere, maybe a build it
path specified at the compile time ? though a "strings libphp4.so"
would show it too.
-- teodor