Re: True DB password protection - is it possible? (repost)

From: Date: Fri, 11 Aug 2000 23:58:39 +0000
Subject: Re: True DB password protection - is it possible? (repost)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-11433@lists.php.net to get a copy of this message
As long as you don't mind haveing a plaintext password in system memory, here's the best way to do it: dbscript.mysql: CREATE TABLE users ( ID int unsigned not null auto_increment, username varchar(65), password varchar(65) ); INSERT INTO users SET username = 'BruceX', password = ENCRYPT(mypassword,az); INSERT INTO users SET username = 'bmcadams', password = ENCRYPT(mypassword,az); We've created a database for users and passwords, and made it very clear that we will be ENCRYPTING (internal MySQL facilitation of unix's one way crypt function) encrypting our passwords with a salt of 'az'. For a truly secure password, create the db on a secure host only you have access to, then copy the ENCRYPTED password fields to the public mysql host. authenticate.php: <? function check_auth() { global $PHP_AUTH_USER; global $PHP_AUTH_PW; $encrypted_pass = crypt($PHP_AUTH_PW,az); // encrypt the password with the az salt if (!$PHP_AUTH_USER) { require_login(); } else { $sth = MYSQL_QUERY("SELECT ID FROM users WHERE username='$PHP_AUTH_USER' AND password = '$encrypted_pass'"); $rows = MYSQL_NUM_ROWS($sth); if ($rows == 0) { require_login(); } else { return 1; } } } // if desired, edit this function to return the user ID... I left that out for simplicity in this example function require_login() { // pop up ye olde authorisation dialog box header('WWW-Authenticate: Basic realm="Secret Hideout"'); header('HTTP/1.0 401 Unauthorized'); echo 'Authorization Required.'; exit; } ?> I leave it up to you for the actual implementation of this code - all it really takes is a compiled-into apache php module, and a 'popup authentication' capable browser. Alternatively, if you are running php as a CGI, you could use the same method with straight form login methods. If you have any questions, let me know ... -brendan On Fri, 11 Aug 2000, Christensen, BruceX R wrote: > I've searched the archives on this issue, and found no conclusive answer to > my question: > > Is it possible to use a password-protected database on a shared virtual > server while limiting the ability of other users to see the password? > > My commercial host runs Apache/mod_php, using <VirtualHost> settings to > serve up multiple domain names. They also offer DB access (MySQL). > However, I haven't been able to think of a good way to protect my password > from other users. To use the db from MySQL, I have to do a mysql_connect() > to open the DB connection, passing the password to that function. The > problem is that the web server runs as nobody (not my username), and so > anyone with access to nobody (in this case all of my fellow virtual host > customers) have access to the same files I do. > > Any ideas on how to keep people out of my data? I've considered encrypting > and decrypting the password; this would add another step to getting the > password, but could easily be circumvented. I /suppose/ that my hosting > company could install my own CGI binary that runs as a different user > (using something like cgiwrap), but I doubt they would. > > Ideas? > > --Bruce > > Bruce Christensen > Intel Corporation > brucex.r.christensen@intel.com > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#11433) next »