True DB password protection - is it possible? (repost)

From: Date: Fri, 11 Aug 2000 22:09:00 +0000
Subject: True DB password protection - is it possible? (repost)
Groups: php.general 
Request: Send a blank email to php-general+get-11422@lists.php.net to get a copy of this message
I've searched the archives on this issue, and found no conclusive answer to my question: Is it possible to use a password-protected database on a shared virtual server while limiting the ability of other users to see the password? My commercial host runs Apache/mod_php, using <VirtualHost> settings to serve up multiple domain names. They also offer DB access (MySQL). However, I haven't been able to think of a good way to protect my password from other users. To use the db from MySQL, I have to do a mysql_connect() to open the DB connection, passing the password to that function. The problem is that the web server runs as nobody (not my username), and so anyone with access to nobody (in this case all of my fellow virtual host customers) have access to the same files I do. Any ideas on how to keep people out of my data? I've considered encrypting and decrypting the password; this would add another step to getting the password, but could easily be circumvented. I /suppose/ that my hosting company could install my own CGI binary that runs as a different user (using something like cgiwrap), but I doubt they would. Ideas? --Bruce Bruce Christensen Intel Corporation brucex.r.christensen@intel.com -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#11422) next »