Re: True DB password protection - is it possible? (repost)
| From: | brendan-lists at earth dot plexmedia dot net | Date: | Fri, 11 Aug 2000 23:58:39 +0000 |
| Subject: | Re: True DB password protection - is it possible? (repost) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-11433@lists.php.net to get a copy of this message | ||
As long as you don't mind haveing a plaintext password in
system memory,
here's the best way to do it:
dbscript.mysql:
CREATE TABLE users (
ID int unsigned not null auto_increment,
username varchar(65),
password varchar(65)
);
INSERT INTO users SET username = 'BruceX', password = ENCRYPT(mypassword,az);
INSERT INTO users SET username = 'bmcadams', password = ENCRYPT(mypassword,az);
We've created a database for users and passwords, and made it very clear
that we will be ENCRYPTING (internal MySQL facilitation of unix's one way crypt function)
encrypting our passwords with a salt of 'az'.
For a truly secure password, create the db on a secure host only you have access to, then copy the
ENCRYPTED password fields to the public mysql host.
authenticate.php:
<?
function check_auth() {
global $PHP_AUTH_USER;
global $PHP_AUTH_PW;
$encrypted_pass = crypt($PHP_AUTH_PW,az); // encrypt the password with the az salt
if (!$PHP_AUTH_USER) {
require_login();
} else {
$sth = MYSQL_QUERY("SELECT ID FROM users
WHERE username='$PHP_AUTH_USER' AND password = '$encrypted_pass'");
$rows = MYSQL_NUM_ROWS($sth);
if ($rows == 0) {
require_login();
} else {
return 1;
}
}
} // if desired, edit this function to return the user ID... I
left that out for simplicity in this example
function require_login() {
// pop up ye olde authorisation dialog box
header('WWW-Authenticate: Basic realm="Secret Hideout"');
header('HTTP/1.0 401 Unauthorized');
echo 'Authorization Required.';
exit;
}
?>
I leave it up to you for the actual implementation of this code - all it really takes is a
compiled-into apache php module, and a 'popup authentication' capable browser.
Alternatively, if you are running php as a CGI, you could use the same method with straight form
login methods.
If you have any questions, let me know ...
-brendan
On Fri, 11 Aug 2000, Christensen, BruceX R wrote:
> I've searched the archives on this issue, and found no conclusive answer to
> my question:
>
> Is it possible to use a password-protected database on a shared virtual
> server while limiting the ability of other users to see the password?
>
> My commercial host runs Apache/mod_php, using <VirtualHost> settings to
> serve up multiple domain names. They also offer DB access (MySQL).
> However, I haven't been able to think of a good way to protect my password
> from other users. To use the db from MySQL, I have to do a mysql_connect()
> to open the DB connection, passing the password to that function. The
> problem is that the web server runs as nobody (not my username), and so
> anyone with access to nobody (in this case all of my fellow virtual host
> customers) have access to the same files I do.
>
> Any ideas on how to keep people out of my data? I've considered encrypting
> and decrypting the password; this would add another step to getting the
> password, but could easily be circumvented. I /suppose/ that my hosting
> company could install my own CGI binary that runs as a different user
> (using something like cgiwrap), but I doubt they would.
>
> Ideas?
>
> --Bruce
>
> Bruce Christensen
> Intel Corporation
> brucex.r.christensen@intel.com
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>