RE: [PHP] how to not send plaintext when using mysql_connect -- REPOST
| From: | Daevid Vincent | Date: | Fri, 27 Oct 2000 00:15:42 +0000 |
| Subject: | RE: [PHP] how to not send plaintext when using mysql_connect -- REPOST | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-22237@lists.php.net to get a copy of this message | ||
perhaps I wasn't clear enough.
mysql has a line like
$linkid = mysql_pconnect( "mysql.mydomain.com", "myuser", "mypass")
or
die( "Unable to connect to mySQL server");
the "myuser" and "mypass" are sent in plaintext across the internet to the
mySQL server "mysql.mydomain.com".
THAT is what is the problem. Those packets can be sniffed by anyone on the
internet that they happen to go through. hence that user can get myuser and
mypass and write their own PHP page to muck around in my database.
to compound the issue, mySQL REQUIRES the myuser and mypass to be IN
plaintext from what I understand, so I can't even do something like this:
$linkid = mysql_pconnect( "mysql.mydomain.com", "myuser",
password("mypass")) or die( "Unable to connect to mySQL server");
or md5() or crypt() or any other form of obfuscation/encryption.
> -----Original Message-----
> From: Dallas Kropka [mailto:dallask@firstworld.net]
> Sent: Thursday, October 26, 2000 7:12 AM
> To: Daevid Vincent
> Cc: PHP LIST
> Subject: Re: [PHP] how to not send plaintext when using mysql_connect --
> REPOST
>
>
> if your passing the log and pass to another script, use sessions....
> otherwise, Include the information in another file...
>
> ex...
> ***********
> connect.inc
> ***********
> $log = "name";
> $pass= "pass";
> ***********
>
> ******
> your script
> ******
> require("connect.inc"):
> ******
>
>
> this will force the passing of variables with out url encodeing. Ive found
> it works well
>
>
>
> ----- Original Message -----
> From: "Daevid Vincent" <DayWalker@TheMatrix.com>
> To: "PHP General" <php-general@lists.php.net>
> Sent: Monday, October 23, 2000 11:32 AM
> Subject: [PHP] how to not send plaintext when using mysql_connect
> -- REPOST
>
>
> > Never got a reply on this one, so I'm hoping the second time
> someone will
> > know the answer. :)
> >
> > -----Original Message-----
> > From: Daevid Vincent [mailto:DayWalker@thematrix.com]
> > Sent: Friday, October 20, 2000 4:07 PM
> > To: PHP General
> > Subject: [PHP] how to not send plaintext when using mysql_connect
> >
> >
> > http://www.php.net/manual/function.mysql-connect.php
> >
> > indicates that I have to use the plaintext version of my
> password... this
> is
> > unacceptable for having the website server connecting to the
> mySQL server
> as
> > it can be sniffed easily.
> >
> > Is there a way to encrypt this information somehow?
> >
> > there is a comment at the bottom of the page, but I'm not sure I
> understand
> > it. It implies that MD5 is done transparently somehow, but I'm
> told by my
> IS
> > department that they are able to sniff the user/password that
> I'm sending
> in
> > my PHP scripts...
> >
> > bdonor@westnet.com
> > 10-Sep-2000 04:22
> >
> > I'm sure most people have figured this out (possibly I missed it in the
> > documentation) but both mysql_connect and mysql_pconnect expect the
> > plaintext password, NOT the MD5 hash of the password. It does
> that all by
> > itself.
> >
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-general-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-general-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
> >
>