RE: [PHP] how to not send plaintext when using mysql_connect -- REPOST

From: Date: Fri, 27 Oct 2000 16:29:46 +0000
Subject: RE: [PHP] how to not send plaintext when using mysql_connect -- REPOST
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-22347@lists.php.net to get a copy of this message
> From: Daevid Vincent [mailto:DayWalker@TheMatrix.com] > Subject: RE: [PHP] how to not send plaintext when using mysql_connect -- > > perhaps I wasn't clear enough. > > mysql has a line like > $linkid = mysql_pconnect( "mysql.mydomain.com", "myuser", > "mypass") or > die( "Unable to connect to mySQL server"); > > the "myuser" and "mypass" are sent in plaintext across the internet to the > mySQL server "mysql.mydomain.com". > > THAT is what is the problem. Those packets can be sniffed by anyone on the > internet that they happen to go through. hence that user can get > myuser and > mypass and write their own PHP page to muck around in my database. > > to compound the issue, mySQL REQUIRES the myuser and mypass to be IN > plaintext from what I understand, so I can't even do something like this: > > $linkid = mysql_pconnect( "mysql.mydomain.com", "myuser", > password("mypass")) or die( "Unable to connect to mySQL server"); > > or md5() or crypt() or any other form of obfuscation/encryption. errr.. what would be the point of having the option of sending an obfuscated password if you're afraid of packet sniffers? Those sniffers can simply grab the obfuscated password and re-use it, without even having to know the original password. / Carsten -- Carsten H. Pedersen keeper and maintainer of the bitbybit.dk MySQL FAQ http://www.bitbybit.dk/mysqlfaq

« previous php.general (#22347) next »