Re: True DB password protection - is it possible? (repost)
| From: | Mike Tuller | Date: | Sat, 12 Aug 2000 00:05:04 +0000 |
| Subject: | Re: True DB password protection - is it possible? (repost) | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-11434@lists.php.net to get a copy of this message | ||
Since the machine is remote, it would be impossible to totally protect the
password, but encryption is a good idea. If you connect from only one
machine, and if you have a static IP address, you could have MySql only
accept commands from that address. It would be nice to go by mac address.
You should ask this on a MySql list.
Mike
----------
>From: "Christensen, BruceX R" <brucex.r.christensen@intel.com>
>To: "'PHP mailing list (E-mail)'" <php-general@lists.php.net>
>Subject: [PHP] True DB password protection - is it possible? (repost)
>Date: Fri, Aug 11, 2000, 5:09 PM
>
> I've searched the archives on this issue, and found no conclusive answer to
> my question:
>
> Is it possible to use a password-protected database on a shared virtual
> server while limiting the ability of other users to see the password?
>
> My commercial host runs Apache/mod_php, using <VirtualHost> settings to
> serve up multiple domain names. They also offer DB access (MySQL).
> However, I haven't been able to think of a good way to protect my password
> from other users. To use the db from MySQL, I have to do a mysql_connect()
> to open the DB connection, passing the password to that function. The
> problem is that the web server runs as nobody (not my username), and so
> anyone with access to nobody (in this case all of my fellow virtual host
> customers) have access to the same files I do.
>
> Any ideas on how to keep people out of my data? I've considered encrypting
> and decrypting the password; this would add another step to getting the
> password, but could easily be circumvented. I /suppose/ that my hosting
> company could install my own CGI binary that runs as a different user
> (using something like cgiwrap), but I doubt they would.
>
> Ideas?
>
> --Bruce
>
> Bruce Christensen
> Intel Corporation
> brucex.r.christensen@intel.com
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net