#37000 [Opn->WFx]: Suggestion for improving Database Security chapter
| From: | danbrown@php.net | Date: | Fri, 08 May 2009 17:27:44 +0000 |
| Subject: | #37000 [Opn->WFx]: Suggestion for improving Database Security chapter | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-2217@lists.php.net to get a copy of this message | ||
ID: 37000
Updated by: danbrown@php.net
Reported By: david at acz dot org
-Status: Open
+Status: Wont fix
Bug Type: Documentation problem
PHP Version: Irrelevant
New Comment:
This isn't so much a database issue as it is a permissions issue. As
such, the permissions and security are inherited by the operating
system's own security (or lack thereof), and thus goes beyond the scope
of the PHP manual.
Previous Comments:
------------------------------------------------------------------------
[2006-04-06 16:19:33] david at acz dot org
Description:
------------
It would be helpful for the Database Security chapter to discuss
security in a shared hosting environment. Under a typical Apache /
mod_php setup where PHP scripts all run as the Apache user, any user can
read any other user's PHP scripts and thus capture any database
authentication information. It may be possible to mitigate this with
safe mode, but not if the server allows running other types of CGIs.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=37000&edit=1