#37000 [Opn->WFx]: Suggestion for improving Database Security chapter

From: Date: Fri, 08 May 2009 17:27:44 +0000
Subject: #37000 [Opn->WFx]: Suggestion for improving Database Security chapter
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-2217@lists.php.net to get a copy of this message
ID: 37000 Updated by: danbrown@php.net Reported By: david at acz dot org -Status: Open +Status: Wont fix Bug Type: Documentation problem PHP Version: Irrelevant New Comment: This isn't so much a database issue as it is a permissions issue. As such, the permissions and security are inherited by the operating system's own security (or lack thereof), and thus goes beyond the scope of the PHP manual. Previous Comments: ------------------------------------------------------------------------ [2006-04-06 16:19:33] david at acz dot org Description: ------------ It would be helpful for the Database Security chapter to discuss security in a shared hosting environment. Under a typical Apache / mod_php setup where PHP scripts all run as the Apache user, any user can read any other user's PHP scripts and thus capture any database authentication information. It may be possible to mitigate this with safe mode, but not if the server allows running other types of CGIs. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=37000&edit=1

« previous php.doc.bugs (#2217) next »