Re: True DB password protection - is it possible? (repost)

From: Date: Mon, 14 Aug 2000 04:55:43 +0000
Subject: Re: True DB password protection - is it possible? (repost)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-11560@lists.php.net to get a copy of this message
How about if you put the mysql_connect statement in an include file and place that file inside a password protected directory? ...Dave "Christensen, BruceX R" wrote: > > I've searched the archives on this issue, and found no conclusive answer to > my question: > > Is it possible to use a password-protected database on a shared virtual > server while limiting the ability of other users to see the password? > > My commercial host runs Apache/mod_php, using <VirtualHost> settings to > serve up multiple domain names. They also offer DB access (MySQL). > However, I haven't been able to think of a good way to protect my password > from other users. To use the db from MySQL, I have to do a mysql_connect() > to open the DB connection, passing the password to that function. The > problem is that the web server runs as nobody (not my username), and so > anyone with access to nobody (in this case all of my fellow virtual host > customers) have access to the same files I do. > > Any ideas on how to keep people out of my data? I've considered encrypting > and decrypting the password; this would add another step to getting the > password, but could easily be circumvented. I /suppose/ that my hosting > company could install my own CGI binary that runs as a different user > (using something like cgiwrap), but I doubt they would. > > Ideas? > > --Bruce > > Bruce Christensen > Intel Corporation > brucex.r.christensen@intel.com > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net -- -------------------- To send e-mail to me replace the domain name with djdesign.com The phony "anti.spam" domain is used to fool newsgroup e-mail address harvestor 'bots. ----------------------

« previous php.general (#11560) next »