True DB password protection - is it possible? (repost)
| From: | Christensen, BruceX R | Date: | Fri, 11 Aug 2000 22:09:00 +0000 |
| Subject: | True DB password protection - is it possible? (repost) | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-11422@lists.php.net to get a copy of this message | ||
I've searched the archives on this issue, and found no conclusive answer to
my question:
Is it possible to use a password-protected database on a shared virtual
server while limiting the ability of other users to see the password?
My commercial host runs Apache/mod_php, using <VirtualHost> settings to
serve up multiple domain names. They also offer DB access (MySQL).
However, I haven't been able to think of a good way to protect my password
from other users. To use the db from MySQL, I have to do a mysql_connect()
to open the DB connection, passing the password to that function. The
problem is that the web server runs as nobody (not my username), and so
anyone with access to nobody (in this case all of my fellow virtual host
customers) have access to the same files I do.
Any ideas on how to keep people out of my data? I've considered encrypting
and decrypting the password; this would add another step to getting the
password, but could easily be circumvented. I /suppose/ that my hosting
company could install my own CGI binary that runs as a different user
(using something like cgiwrap), but I doubt they would.
Ideas?
--Bruce
Bruce Christensen
Intel Corporation
brucex.r.christensen@intel.com
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net