Re: Is this secure enough?

From: Date: Sun, 20 Aug 2000 21:55:02 +0000
Subject: Re: Is this secure enough?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-12680@lists.php.net to get a copy of this message
Dave. The best thing to do to keep data safe is to figure out who you're keeping it safe from and at the same time, realize the tradeoffs in keeping it secure. So, do you want to keep the MySQL data secure from . Shell users on your server (people with shell access to the same machine you're on) or . Web users First, if it's shell users you're worried about, make sure the permissions on the directory where you keep the data prohibits them from seeing anything inside that directory. I'll assume you're using Unix of some degree, but the principle is the same for NT. I'll also assume that you need pretty liberal permissions so the webserver (including PHP) can read your files. The best way to do this then is to 'chmod 744' the directory the secure files are in. This means that no one can get a directory listing in those directories except the owner of the directory, but they can access a file if they know its exact name. Since PHP knows the exact name of the file, it can read it. Other shell users on the machine probably don't know the name of the file. If its web users you're worried about, you need to make an include directory BENEATH (or parallel to) the web root for your server. For instance, on the computers at my university, my web root is '/home/hall/public_html'. Well, I would make a directory called '/home/hall/include' for all my PHP includes (the .inc files, not the .php files). That way web users can't even see them -- and couldn't access them if they wanted to. Keeping them in the cgi-bin keeps them available to attack. If someone wants them, they can get them from the web -- whether you have password-protection or not. Dean Hall. ----- Original Message ----- From: "Dave Jones" <dave@anti.spam> To: <php-general@lists.php.net> Sent: Sunday, August 20, 2000 4.14 pm Subject: [PHP] Is this secure enough? > I jsut finished my first real php site and want to make sure there's > nothing I left out as far as unauthorized people getting to my php code > and MySQL data. > > I'm on a shared server (virtual domains on a web host). As far as I > know the domains are kept from looking at each other with .htaccess > (which I know isn't perfect, but should stop casual snoops). > > I have the php code that connects to the database (and contains my > MySQL username, password, and database name) inside an include file > which is stored in a subdirectory of my cgi-bin directory, and that > subdirectory is password protected (again, .htaccess). The rest of the > php is just in the pages spread throughout the web accessable folders. > > The only other thing I could come up with is to put all of the page > content (for all pages) inside include files that are in a password > protected folder and the public files contain nothing but one include > statement each, but this seems to be getting too paranoid. > > Since this is a shared server, I don't have access to configuring php > or MySQL (and the host is too large and accounts too cheap to ask for > anything special in that vein). Is this about as good as I can do for > security? > > ...Dave > > > -------------------- > To send e-mail to me replace the > domain name with djdesign.com > The phony "anti.spam" domain > is used to fool newsgroup e-mail > address harvestor 'bots. > ---------------------- > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#12680) next »