Re: True DB password protection - is it possible? (repost)
| From: | Dave Jones | Date: | Mon, 14 Aug 2000 04:55:43 +0000 |
| Subject: | Re: True DB password protection - is it possible? (repost) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-11560@lists.php.net to get a copy of this message | ||
How about if you put the mysql_connect statement in an include file
and place that file inside a password protected directory?
...Dave
"Christensen, BruceX R" wrote:
>
> I've searched the archives on this issue, and found no conclusive answer to
> my question:
>
> Is it possible to use a password-protected database on a shared virtual
> server while limiting the ability of other users to see the password?
>
> My commercial host runs Apache/mod_php, using <VirtualHost> settings to
> serve up multiple domain names. They also offer DB access (MySQL).
> However, I haven't been able to think of a good way to protect my password
> from other users. To use the db from MySQL, I have to do a mysql_connect()
> to open the DB connection, passing the password to that function. The
> problem is that the web server runs as nobody (not my username), and so
> anyone with access to nobody (in this case all of my fellow virtual host
> customers) have access to the same files I do.
>
> Any ideas on how to keep people out of my data? I've considered encrypting
> and decrypting the password; this would add another step to getting the
> password, but could easily be circumvented. I /suppose/ that my hosting
> company could install my own CGI binary that runs as a different user
> (using something like cgiwrap), but I doubt they would.
>
> Ideas?
>
> --Bruce
>
> Bruce Christensen
> Intel Corporation
> brucex.r.christensen@intel.com
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
--
--------------------
To send e-mail to me replace the
domain name with djdesign.com
The phony "anti.spam" domain
is used to fool newsgroup e-mail
address harvestor 'bots.
----------------------